How to remove the unverified sender message?

Anonymous
2024-07-01T09:11:57+00:00

Hi,

I keep getting an 'unverified sender' message in Outlook (desktop and web app). I've added the address to 'trusted sender' and I've whitelisted the domain but still keep getting it.

The sender is 'trusted' and a reputable domain.

Is there anything else I can do on my side or is it down to the sender?

Many thanks,

Charlie

Outlook | Windows | New Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

82 answers

Sort by: Most helpful
  1. Anonymous
    2025-01-18T00:05:42+00:00

    For those still looking for an answer... We ran into this with our Spiceworks Cloud ticket system emails and us using an internal email address for delivery.

    You will need access to the 365 Security Admin Center: https://security.microsoft.com/tenantAllowBlockList?viewid=SpoofItem

    Add an Internal AND External "allow" for the spoof'd sender address along with the actual sender's DKIM-passing domain. So for us, the entry is: *** Email address is removed for privacy ***, on.spiceworks.com

    Note, the email headers will show the DKIM-passing domain. Just look for the domain name just before "dkim=pass (signature was verified)".

    Thank you for that URL! I was receiving "Unverified"-tagged emails from Salesforce because they were spoofing as an internal email address we have here.

    I have a Power Automate flow that wasn't triggering when these emails came in. I suspected it was due to the "Unverified" tag.

    Instead of a "dkim=pass (signature was verified)" line, mine said "dkim=none". ChatGPT told me to add the records as

    my_internal_email_at_company_dot_com, salesforce_dot_com
    

    The emails no longer come in as Unverified, and they trigger the Flow. Hopefully it stays that way.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-01-10T17:07:53+00:00

    For those still looking for an answer... We ran into this with our Spiceworks Cloud ticket system emails and us using an internal email address for delivery.

    You will need access to the 365 Security Admin Center: https://security.microsoft.com/tenantAllowBlockList?viewid=SpoofItem

    Add an Internal AND External "allow" for the spoof'd sender address along with the actual sender's DKIM-passing domain. So for us, the entry is: ******@ourdomain.com, on.spiceworks.com

    Note, the email headers will show the DKIM-passing domain. Just look for the domain name just before "dkim=pass (signature was verified)".

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-10-03T08:51:30+00:00

    This kind of misses the point ... the issue is we have no control over what email is allowed or not to be visible in our inbox thanks to Microsofts' control over this - there is an option to delete a message or only see some of it on a growing number of messages. Other messages come with an option to trust or not, and that approach works fine - I can decide if an organisation can be trusted or is genuine based on my past history with the compny in question.

    The issue I have is with those that Microsoft have decided are dangerous and only provide me the 'option' to delete ...even when the email is 100% genuine. This is NOT appropriate, and as a small business owner who is 100% reliant on getting all emails from customers and suppliers, I have zero control over whether an organisation has bothered to sort their DMARC responsibilities or not.

    I should be allowed, during this 'changeover' period while DMARC becomes more widely adopted, to decide whether to accept an email or not. I need the information in many emails that are being blocked, and as a result my company is losing out.

    The fact that a huge amount of spam is STILL getting through and genuine emails are being blocked with no way of unblocking them (adding to safe sender etc does squat) suggests that currently this system is less than useful in its' present form.

    But I am sure your reply may be helpful to someone who is looking to add DMARC to their own business.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-10-03T08:01:39+00:00

    The "unverified sender " tag is there to indicate that the email in question is not passing DMARC, an industry standard set up to prevent attackers spoofing domains to deliver phishing messages.

    The DMARC organization explains the technology here dmarc.org – Domain Message Authentication Reporting & Conformance

    More and more services will not accept email *unless* it passes DMARC, so there is a requirement by domain owners to publish records in accordance with their sending infrastructure in order to demonstrate that the sender is who they say they are (or authorized to send on their behalf)

    To prevent the "unverified sender" tag from showing in Outlook, you can follow these steps:

    Verify Email Authentication: Ensure that the sender's domain has proper email authentication methods set up, such as SPF, DKIM, and DMARC. These protocols help verify the sender's identity and ensure the email is not spoofed.

    Configure Anti-Phishing Policies: In the anti-phishing policies in both EOP and Defender for Office 365, you can adjust the settings for unauthenticated sender indicators. This includes turning off the setting that adds a question mark to the sender's photo if the message doesn't pass SPF or DKIM checks.

    Allow Spoofed Senders: You can manually allow the spoofed sender in the spoof intelligence insight or in the Tenant Allow/Block List. This will prevent the "via" tag from appearing in messages from the sender when unauthenticated sender identification is disabled.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-08-21T21:16:18+00:00

    I HAVE THE SAME COMPLAINT! TURN IT OFF!! IT IS RIDICULOUS THAT YOU PUT SUCH A BURDEN UPON THE USER AFTER HAVING TO BUY YOUR SERVICE WE NOW HAVE TO WORK FOR YOU!? WE HAVE ALREADY WAIVED ALL OUR RIGHTS AGAINST YOU.

    Searching for another platform right now and expect an Exodus. You are interrupting business.

    I expect a response with an answer to my one question: Are you going to fix this or not?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments