Skip to content

“Is this email real?”

That weekly question already has a named, repeatable answer.

Spam and phishing triage, Defender for Office 365 tuning, and a clear first step after a clicked link are named parts of everyday support—not a promise of round-the-clock security monitoring the desk cannot back up.

Request path

Spam and phishing triage

You are unsure whether a specific message is real.

Representative situations

  • A message that looks like a known contact but reads oddly
  • An invoice, delivery notice, or password-reset email you did not expect
  • A message that reached the inbox that should have been filtered as spam
  • A legitimate sender landing in junk instead of the inbox

Request path

Defender for Office 365 tuning

The filter keeps getting the same kind of message wrong.

Representative situations

  • A specific sender pattern keeps arriving despite being reported repeatedly
  • A safe, expected sender keeps landing in quarantine
  • An anti-phishing or Safe Links policy behaving differently for one group
  • A new impersonation pattern worth a policy adjustment

If you already clicked, opened, or typed something

Do this now—not a full explanation first.

  • Stop entering anything elseClose the page or app before clicking or typing further, even if it asks you to “confirm” or “verify.”
  • Say what happened, and whenWhat you clicked, opened, or typed, and roughly what time—guessing later is harder than noting it now.
  • “I think I clicked something” is enoughA complete, useful report does not need a full diagnosis attached to it.
  • Change what you still can, safelyIf you still have access, changing the password you used while you wait for a response is reasonable.

Read the message

Four patterns worth a second look, before you click anything.

None of these prove a message is fake on their own—together, they are usually reason enough to check first.

It creates urgency

A deadline, a threat, or a “final notice” pushing you to act before you would normally check.

It asks for something odd

A password, a gift card, an invoice change, or an approval for something you did not request.

The sender almost matches

A display name that looks right but an address that is one character off, or a reply-to that does not match.

It arrived at an odd time or channel

Off-hours, from a personal address claiming to be a colleague, or unusually formatted for that sender.

Set the expectation

Support, not a security operations centre.

Is this a 24/7 monitored operations centre?
No. Email security support runs inside the same desk relationship as everyday requests—there is no continuously staffed operations centre or published alerting SLA.
Does the desk investigate a serious compromise end to end?
No. The desk applies routine containment once flagged and names what it found; a full investigation, legal, or insurance question stays with your business or a security specialist.
Will a real message from the desk ask me to click or confirm something?
No. That request pattern is the reason to refuse it, regardless of who appears to be asking.
Is ongoing filter tuning included with Essential?
Reporting and routine triage is everyday support on both plans. A recurring tuning review sits closer to the light security-baseline support named on the Plus plan.

If a higher licence tier is the actual fix

Common questions

What the desk will and will not ask you to do.

Will the desk ever ask me to confirm my password by email?

No. A real request from the desk never asks you to click a link, confirm a password, or approve an MFA prompt to “verify” anything—that pattern is the request to refuse, from anyone.

Does reporting a message that turns out to be safe waste anyone’s time?

No. A quick check on a message you are unsure about is exactly what this lane is for, real or not. A clicked link costs more than a question.

Is Defender for Office 365 already part of our licensing?

That depends on which Microsoft 365 plan your business already holds. The desk can confirm what your current licensing includes and tune the policies available inside it—upgrading to unlock more is a licensing decision, not a setting change.

Related guides

Sign-in risk connects to policy and password resets.

Conditional Access and MFA policy setup →Password and MFA resets →