Skip to content
5 min fix Updated 8 Aug 2026Beginner
Quick Answer

Go to security.microsoft.com/quarantine and sign in with your work account. Select the held message, click Preview message to check it safely, then click Release. If the button reads Request release, your IT team approves it instead.

How to Release a Quarantined Email in Microsoft 365

Applies to: Microsoft 365 (Outlook, New Outlook, Outlook on the web)
Article Type: How-To
Last Updated: 2026-08-08

Summary

An email you were expecting has not arrived, it is not in Junk, and the sender confirms they sent it. Microsoft 365's server-side filter may be holding it in quarantine — and you can check that yourself, without a ticket, at security.microsoft.com/quarantine. This article shows you how to review a held message safely, release it when it is genuine, and recognize the fake "quarantine" emails that imitate the real notification.

Before You Start

  • A Microsoft 365 work or school account. Quarantine is a Microsoft 365 feature — personal Outlook.com accounts use the Junk Email folder instead.
  • Any web browser. No admin rights are needed to view your own quarantine.
  • Quarantined messages are held for a limited time — up to 30 days, depending on your organization's settings — and then permanently deleted, so check within that window.

Instructions

1. Open Your Quarantine Page

Quarantine has its own self-service page — you do not need IT to see what is being held for you.

  1. Open your browser, type security.microsoft.com/quarantine in the address bar, and press Enter.
  2. Sign in with your work email and password if prompted.
  3. The Quarantine page of the Microsoft Defender portal opens. On the Email tab you see a list of held messages — each row shows when it arrived, the subject, the sender, and the reason it was held (such as Spam or Phish).
  4. If the list is empty, nothing addressed to you is currently in quarantine. That is a real answer, not an error — see Troubleshooting for where to look next.

2. Recognize the Real Quarantine Digest

Microsoft can also email you a summary of held messages — and attackers imitate that exact email to steal passwords.

  1. The genuine digest arrives from [email protected] with the subject "You have messages in quarantine", and lists each held message with Review Message and Release links.
  2. Treat the digest as a notification, not a doorway. Instead of clicking its buttons, open security.microsoft.com/quarantine yourself as in step 1 — a real digest never mentions anything that page does not also show, so you lose nothing by ignoring its links.
  3. Treat a "quarantine" email as fake if it leads to a sign-in page on a non-Microsoft address, asks for your password to "verify" a release, or carries an attachment. How to Spot Fake Microsoft Login Pages shows you how to check the sign-in address in seconds.
  4. If the digest is fake, select it in Outlook and click Report > Report phishing. It leaves your inbox and your security team is alerted.

3. Preview the Held Message

Preview is read-only and safe — it shows you what the message says without delivering it or activating anything inside it.

  1. On the Quarantine page, click the message's row. A details panel opens on the right, showing the sender, subject, and the reason the message was held.
  2. Click Preview message. The message body appears in a safe viewer; attachments are not opened.
  3. Read it with one question in mind: were you expecting this message, from this sender, about this topic? Do not click any links inside the preview.
  4. Close the preview when you are done. The message stays sealed in quarantine — previewing changes nothing, so you can look as many times as you need.

4. Release the Message

Releasing delivers the message to your inbox, so it is a decision, not a formality — release only what you were expecting from a sender you trust.

  1. In the details panel, click Release (labelled Release email in some layouts).
  2. Confirm when prompted. The message's status on the Quarantine page changes to Released.
  3. The email arrives in your Inbox within a few minutes.
  4. Releasing one message does not change future filtering. If the same sender keeps getting caught, add them to your Safe Senders list — see How to Manage Junk Mail and Spam Filters in Outlook.
  5. If you release a message and then have second thoughts, the situation is recoverable: do not click anything inside it, report it with Report > Report phishing, and delete it. Releasing moved the message — it did not grant it any trust.

5. Use Request Release When That Is All You See

For some categories — most often messages flagged as phishing — your organization reserves the final decision for an admin, and the button changes to match.

  1. If the details panel shows Request release instead of Release, click it. The message's status changes to Release requested and your IT team is notified.
  2. Wait for the decision. If IT approves, the message arrives in your Inbox; if they decline, it stays in quarantine — which usually means they found something you could not see from the preview.
  3. If the request sits unanswered and the message matters, raise a ticket: Ask IT to release the message with subject [subject] quarantined on [date], and say why you trust the sender — for example, "this is the invoice we were expecting this week from our regular supplier."

6. Know When Not to Release

Leaving a doubtful message sealed costs you nothing — quarantine deletes it automatically when the holding period ends.

  • Do not release a message that asks you to sign in, "verify" an account, or "confirm" a payment — that pattern is phishing no matter who appears to have sent it. How to Identify a Phishing Email lists the tells.
  • Do not release an invoice, parcel notice, or voicemail alert you were not expecting. Attackers use those disguises precisely because they sound like normal business.
  • Do not release a message with an attachment you were not told to expect, even from a name you know — sender names and addresses are routinely faked.
  • When genuinely unsure, ask the sender through another channel — a call or a Teams message — whether they sent it. If they did not, leave it sealed.

Troubleshooting

WARNING

A "quarantine" email that leads to a sign-in page is the attack, not the notification. Whenever a held-email notice makes you hesitate, skip its buttons entirely and type security.microsoft.com/quarantine into your browser yourself — the real list is always there, and it never asks you to re-enter your password on an unfamiliar page.

Symptom / ErrorPotential CauseSolution
The quarantine page shows an error or refuses to loadYour organization keeps the quarantine portal admin-onlyAsk IT to release the message with subject [subject] quarantined on [date], and say why you trust the sender.
The expected email is not listed in quarantineIt was never quarantined, or it is in an admin-only category such as malwareSearch all your mail folders first — see How to Fix Missing or Disappeared Emails in Outlook. Still missing? Ask IT to trace the message and include the sender's address and the date it was sent.
Released message never arrives in the InboxDelivery takes a few minutes, or an inbox rule moved itWait five minutes, then search for the subject line — a rule may have filed it in another folder.
The same sender lands in quarantine again and againThe filter keeps scoring that sender as suspiciousAdd the sender to your Safe Senders list (see How to Manage Junk Mail and Spam Filters in Outlook). If it continues, ask IT to add the sender to the organization-wide allow list and include one example (sender, date, subject).
A quarantine digest looks offPhishing imitation of the real digestDo not click its buttons. Check the portal directly, then report the email with Report > Report phishing.