Identify Suspicious Messages
Outlook verifies that the sender is who they say they are and marks malicious messages as junk email. If the message is suspicious but isn't deemed malicious, the sender will be marked as unverified to notify the receiver that the sender may not be who they appear to be.
Important: When a message is marked as a phishing message, Outlook displays a warning at the top of the page, but any links in the message can still be opened.
How can I identify a suspicious message in my inbox?
Outlook shows indicators when the sender of a message is unverified, and either can't be identified through email authentication protocols or their identity is different from what you see in the from address.
-
You see a '?' in the sender image. When Outlook can't verify the identity of the sender using email authentication techniques, it displays a '?' in the sender photo.
- Below safety tips appear in outlook web, desktop, and mobile clients and notify recipients the first time they get a message from the sender or if they don’t often get messages from the sender. This capability adds an extra layer of security protection against impersonation attacks. Email spoofing involves an external email address impersonating a staff or faculty member to mislead, manipulate, and scam an unsuspecting victim. The purpose of this message is to make the recipient aware that the message originated from outside our organization. A sample message can be seen below.
- Not every message that fails to authenticate is malicious. However, you should be careful about interacting with messages that don't authenticate if you don't recognize the sender. Or, if you recognize a sender that normally doesn't have a '?' in the sender image, but you suddenly start seeing it, that could be a sign the sender is being spoofed.
- The sender's address is different than what appears in the from address.
- Please be aware about the expected and unexpected emails. Please verify unexpected email from the sender before acknowledging or making any action on the email.
Frequently, the email address you see in a message is different than what you see in the from address. Sometimes phishers try to trick you into thinking that the sender is someone other than who they really are.
When Outlook detects a difference between the sender's actual address and the address on the from address, it shows the actual sender using the via tag, which will be underlined.
In this example, the sending domain "suspicious.com" is authenticated, but the sender put "unknown@contoso.com" in the from address.
Not every message with a via tag is suspicious. However, if you don't recognize a message with a via tag, you should be cautious about interacting with it.
In Outlook you can hover your cursor over a sender's name or address in the message list to see their email address, without needing to open the message.
If you have concerns about this, please feel free to reach out to IT team.