Skip to main content

Report Junk & Phishing Button

The Outlook report button can be used to share potential false negatives and false positives with your help desk and the Mesh detection team.

1658159116.png
image-20250110-100852.png

Sharing reported messages with the detection team helps improve filtering based on user feedback and enables notifications for potential spam, phishing, and false positives.

Note

The reporting mailbox is largely automated, and neither you nor the end user will receive a response. To discuss a false positive or false negative, contact Technical Support. For contact information, see Bitdefender Technical Support.

Configure the button experience and report destination

  1. Open Microsoft Security Center

    Go to the Microsoft Security Center, and then select Settings > Email & collaboration > User reported settings.

    image-20250107-113449.png
    image-20250107-113402.png
  2. Configure the reporting experience

    Enable the following options:

    • Monitor reported messages in Outlook.

    • Use the built-in Report button in Outlook.

    • Ask the user to confirm before reporting.

    • Show a success message after the message is reported.

    image-20250107-113853.png
  3. Configure the reporting destination

    For Send reported messages to, select:

    My reporting mailbox only.

    Note

    The specified email address must be a mailbox in the customer’s tenant.

    image-20250107-113655.png

Create a mail flow rule for the Report button

This mail flow rule allows you to copy reported messages to mailboxes outside the customer’s tenant.

  1. Open the Microsoft Exchange admin center

    Go to the Microsoft Exchange admin center, and then select Mail flow > Rules.

  2. Add a rule

    Select Add a rule > Create a new rule.

  3. Configure the rule conditions

    Enter a name for the rule, and then apply the following conditions:

    The sender > is external/internal > Inside the organization.

    AND   

    The message headers > matches these text patterns.

    Set the x-ms-exchange-antispam-submissionids message header to match \w.

    AND   

    The subject or body > Subject includes any of these words.

    Add Phishing, and then add Junk.

    image-20250108-144038.png
  4. Configure the rule action

    Select Add recipients > Copy (Cc) the message to, and then add o365-submission@meshsecurity.io and any other required recipients.

    image-20250108-144102.png

    Note

    We recommend copying an address at your MSP, such as your security team or help desk, to maintain visibility of reported messages.

    Use Live Email Tracker to verify the message verdict. If the message is a missed detection, use Remediate to remove it from affected mailboxes. If it is a false positive, create an allow rule or verify whether the active policy options caused the message to be moved to the Junk folder.

  5. Review and finish

    Keep the default rule settings, and then select Next.

    image-20250108-144131.png
  6. Enable the rule

    New mail flow rules are disabled by default. In the Rules table, select the Mesh Report Button rule, and then enable it.

    image-20250108-144341.png