Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Investigate the reported message, establish whether it is malicious, and identify all matching copies before removing anything. Microsoft 365 administrators can use Microsoft Defender for Office 365’s Threat Explorer or Real-time detections; Google Workspace administrators can use the Security investigation tool and Gmail log events. Available searches and actions depend on your plan, edition, role, and tenant configuration.

1. Preserve the report and identify the message

Keep the original report and capture enough detail to distinguish the message from similar legitimate mail. Record the reporter, report time, subject, sender address, recipient, message identifiers and headers when available, URLs, attachment names, and what the reporter did after receiving it. A display name or subject alone is not a reliable basis for matching messages.

Preserve relevant evidence according to your organization’s incident procedures. The platform guidance below explains how to investigate and act, but it does not establish a universal evidence-preservation checklist; follow local policy.

2. Determine whether the message is malicious

Review message details, sender and delivery information, links or attachments, and available security verdicts. In Microsoft Defender for Office 365, Threat Explorer or Real-time detections provides message results and an email entity view for investigation. Microsoft cautions that a phishing classification and a URL verdict are separate data points: the absence of a URL marked malicious does not, by itself, settle the message’s status. See Microsoft’s Threat Explorer documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Bitdefender Total Security - 5 Devices | 1 year Subscription | PC/Mac | Activation Code by email
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows, Mac OS, iOS, and Android. Organize and keep your digital life safe from hackers.
  • ADVANCED THREAT DEFENSE: Your software is always up-to-date to defend against the latest attacks, and includes: complete real-time data protection, multi-layer malware, ransomware, cryptomining, phishing, fraud, and spam protection, and more.
  • SUPERIOR PRIVACY PROTECTION: including a dedicated safe online banking browser, microphone monitor, webcam protection, anti-tracker, file shredder, parental controls, privacy firewall, anti-theft protection, social network protection, and more.
  • TOP-TIER PERFORMANCE: Bitdefender technology provides near-zero impact on your computer’s hardware, including: Autopilot security advisor, auto-adaptive performance technology, game/movie/work modes, OneClick Optimizer, battery mode, and more

Google Workspace administrators can use the Security investigation tool to find users who received a reported malicious message. Google notes that log data can take a few minutes to become available. See Google’s instructions for investigating reports of malicious emails.

If the evidence is inconclusive, use your organization’s approved investigation process and seek vendor review where appropriate. Do not treat an employee report as proof of maliciousness, or as a reason to delete messages before validating them.

Rank #2
Sale
Bitdefender Total Security - 10 Devices | 2 year Subscription | PC/MAC |Activation Code by email
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows, Mac OS, iOS, and Android. Organize and keep your digital life safe from hackers.
  • ADVANCED THREAT DEFENSE: Your software is always up-to-date to defend against the latest attacks, and includes: complete real-time data protection, multi-layer malware, ransomware, cryptomining, phishing, fraud, and spam protection, and more.
  • SUPERIOR PRIVACY PROTECTION: including a dedicated safe online banking browser, microphone monitor, webcam protection, anti-tracker, file shredder, parental controls, privacy firewall, anti-theft protection, social network protection, and more.
  • TOP-TIER PERFORMANCE: Bitdefender technology provides near-zero impact on your computer’s hardware, including: Autopilot security advisor, auto-adaptive performance technology, game/movie/work modes, OneClick Optimizer, battery mode, and more

3. Find the message’s organization-wide scope

Search with reliable message attributes, then inspect recipients and delivery locations. Validate the matches before taking bulk action, particularly if similar legitimate messages may exist.

Microsoft 365

Use Explorer or Real-time detections in Microsoft Defender for Office 365 to investigate suspicious or delivered malicious messages. Microsoft says these tools can help find and delete messages, identify a sender’s IP address, or start an incident for further investigation. The available functions vary by interface and plan. See Microsoft’s investigation overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
McAfee Total Protection, Text, Email, Video Scam Protection | Auto-Renews
  • ALL-IN-ONE SCAM DETECTION – Texts, emails, videos, and QR codes all get checked automatically. Sorting real from fake stops being your job.
  • KEEP SCAMMERS OUT OF YOUR WALLET – Every click is no longer a gamble. Our scam detection spots suspicious texts, email scams, SMS phishing, and fake alerts before you click.
  • QR CODE SCANNING – Point the app at any code and see where it actually leads before you scan it.
  • DEEPFAKE DETECTION – When a video sounds like someone you know but isn't, you hear it from us first.
  • ON-DEMAND CHECKS – Got a message you're unsure about? Run it through the app and know in seconds, wherever it came from.

Google Workspace

Use the Security investigation tool and relevant Gmail log events to identify users in your domain who received the message. Available data sources vary by Workspace edition. See Google’s investigation instructions.

4. Remove confirmed malicious copies

Act only after confirming the message is malicious and checking that the search results identify the intended copies. Your permissions and the platform’s available actions determine what you can do.

Rank #4
Sale
McAfee Total Protection 2027 Antivirus Software for 1 Device | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.

Microsoft Defender for Office 365

Use the available action in Threat Explorer or Real-time detections for the confirmed messages. Microsoft documents removing identified malicious messages from recipient mailboxes, but the action sets differ between these interfaces and some actions require specific roles. Check the current Microsoft investigation guidance and action and permission details before acting. The investigation article was updated July 3, 2026; features and permissions can change.

Google Workspace

Use the investigation tool to delete messages that match the relevant Gmail log events. Google also documents actions such as marking messages as spam or phishing and sending them to quarantine. Available data sources depend on Workspace edition. Review Google’s guidance for taking action on search results, and verify the selected messages before applying an action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Bitdefender Family Pack - 15 Devices | 2 year Subscription | PC/Mac | Activation Code by email
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows, Mac OS, iOS, and Android. Organize and keep your digital life safe from hackers.
  • ADVANCED THREAT DEFENSE: Your software is always up-to-date to defend against the latest attacks, and includes: complete real-time data protection, multi-layer malware, ransomware, cryptomining, phishing, fraud, and spam protection, and more.
  • SUPERIOR PRIVACY PROTECTION: including a dedicated safe online banking browser, microphone monitor, webcam protection, anti-tracker, file shredder, parental controls, privacy firewall, anti-theft protection, social network protection, and more.
  • TOP-TIER PERFORMANCE: Bitdefender technology provides near-zero impact on your computer’s hardware, including: Autopilot security advisor, auto-adaptive performance technology, game/movie/work modes, OneClick Optimizer, battery mode, and more
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Check for compromise beyond the inbox

Removing a message does not address possible account, identity, or endpoint compromise. Follow your incident-response process if an employee opened an attachment, entered credentials, approved a sign-in, or otherwise interacted with the message. Determine whether further investigation or response is needed.

CISA recommends planning incident response with security and IT teams and relevant business roles. It also recommends enabling useful system and cloud-service logs, protecting them from unauthorized access or deletion, and retaining them according to policy and compliance needs. See CISA’s incident coordination guidance and CISA’s logging guidance.

6. Record the investigation and outcome

Document the report, evidence reviewed, message classification, scope of matching messages, affected users, actions and their status, escalation decisions, and communication to the reporter. Follow organizational policy and applicable requirements for the exact record fields and retention period.

How the Microsoft and Google workflows differ

Area Microsoft 365 Google Workspace
Investigation surface Threat Explorer or Real-time detections in Microsoft Defender for Office 365, according to plan. Security investigation tool using Gmail log events.
Documented remediation Remove identified malicious messages from recipient mailboxes; action sets differ by interface. Delete messages matching relevant Gmail log events; other documented actions include marking as spam or phishing and sending to quarantine.
Access constraints Plan and role can affect available features and actions. Workspace edition affects available data sources.
Timing note No timing estimate stated in the cited Microsoft guidance. Google says log data may take a few minutes to become available.

These tools are not interchangeable, and a tenant may not have every capability described here. Confirm access and available actions in your organization’s configuration and the current vendor documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.