Microsoft Defender for Office 365
Email and collaboration

Submissions User Reported Messages Custom Mailbox

In brief

The documentation now states that reporting mailboxes cannot be distribution groups or external/on-premises mailboxes. It also notes that default investigation-result emails are localized to each recipient’s preferred language.

What Defender admins need to know

Review mailbox configuration and notification expectations; no administrator action is explicitly required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • msecd-doc-authoring-1016 description: Configure where user reported messages go for analysis in Microsoft Defender for Office 365. Set up a reporting mailbox and choose Microsoft, mailbox-only, or both. ms.service: defender-office-365 ms.date: 08/07/03/2026 appliesto:

  • Built-in security features for all cloud mailboxes

  • Microsoft Defender for Office 365 Plan 1 and Plan 2 |Show a success (pop-up) message after the message is reported|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_absent_icon.png":::| |Customize (pop-up) messages for Report phishing, Report junk, Report not junk, Phishing reported, and Junk reported in up to seven languages|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_absent_icon.png":::| |Reported item destination|

    • Microsoft and reporting mailbox
    • Reporting mailbox only
    • Microsoft only
    |
    • Microsoft and reporting mailbox
    • Reporting mailbox only
    | |Email users the results of the investigation|investigation. Default result emails are localized based on the recipient's preferred language.|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::| |Customize the body and footer of the results email for Phishing, Junk, and No threats found|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::| |Customize the logo in all reporting experiences|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::| |Allow reporting for quarantined items|:::image type="icon" source="media/feature_present_icon.png":::|:::image type="icon" source="media/feature_present_icon.png":::|

  • My reporting mailbox only: User reported messages go only to the specified reporting mailbox for an admin or the security operations team to analyze.

    Follow the instructions in the Microsoft and my reporting mailbox option to select the mailbox in the Add an Exchange Online mailbox to Send reported items to box. Distribution groups and routing to an external or on-premises mailbox aren't allowed.

    On the User reported tab on the Submissions page at https://security.microsoft.com/reportsubmission?viewid=user, the Result value for these entries is Not Submitted to Microsoft. Messages don't go to Microsoft for analysis unless an admin manually submits the message. For instructions, see Submit user reported messages to Microsoft for analysis.

  • Email notifications section: These options affect the notification email message that's sent to users when an admin selects :::image type="icon" source="media/defender-portal-icon-mark-and-notify.png" border="false"::: Mark as and notify on the Submissions page at https://security.microsoft.com/reportsubmission. The following options are available:

    The default admin review outcome email is automatically localized based on the recipient's preferred language. This default template is used for manual Mark as and notify actions and automatic investigation result notifications. If you customize the email body or footer, recipients receive the text that you configure instead of the localized default text.

    • Results email section:
      • Select Customize results email. In the Customize admin review email notifications flyout that opens, configure the following settings on the Phishing, Junk, and No threats found tabs:
        • Email body results text: Enter the custom text to use. You can use different text for Phishing, Junk, and No threats found.
  • Email notifications section: These options affect the notification email message that's sent to users when an admin selects :::image type="icon" source="media/defender-portal-icon-mark-and-notify.png" border="false"::: Mark as and notify on the Submissions page at https://security.microsoft.com/reportsubmission. The following options are available:

    The default admin review outcome email is automatically localized based on the recipient's preferred language. This default template is used for manual Mark as and notify actions and automatic investigation result notifications. If you customize the email body or footer, recipients receive the text that you configure instead of the localized default text.

    • Results email section:
      • Select Customize results email. In the Customize admin review email notifications flyout that opens, configure the following settings on the Phishing, Junk, and No threats found tabs:
        • Email body results text: Enter the custom text to use. You can use different text for Phishing, Junk, and No threats found.