Notification emails missing or in junk (Outlook and Microsoft 365)
Overview
Mobile Message can email you every time someone texts your number. See Notifications - getting email alerts for replies and unsubscribes for how to turn this on.
If those emails arrive for some messages but not others, or have stopped arriving altogether, and your mailbox is hosted by Microsoft (Outlook.com, Hotmail, or a business mailbox on Microsoft 365 / Exchange Online), the cause is almost always Microsoft's filtering holding the emails back. The messages themselves are safe. Every inbound SMS is always available in the Messenger, whether or not the email arrived.
Why this happens
Every notification email is sent from sms.mobilemessage.com.au and passes all of Microsoft's own authentication checks (SPF, DKIM and DMARC), so Microsoft can verify it genuinely came from us. Even so, Microsoft's filters sometimes misclassify these emails as junk or as suspected phishing and hold them without telling either of us. This is a false positive on Microsoft's side, and it is a known problem for automated notification emails from many services, not just Mobile Message.
Because Microsoft accepts the email before filtering it, our sending logs show it as delivered. The steps below tell Microsoft that these emails are legitimate.
Step 1: Check Junk and quarantine, and note the reason
Look in the Junk Email folder of the mailbox that receives the notifications.
If you are on Microsoft 365, also check the quarantine. Users can see their own quarantined mail at security.microsoft.com/quarantine, and administrators can see the whole organisation's. Release any Mobile Message notifications you find there.
The quarantine view shows the reason Microsoft gave for holding each message. That reason decides which fix you need:
- Spam, High confidence spam or Bulk, or the emails are simply in the Junk folder: Step 2 is usually enough.
- Phish or High confidence phish: go straight to Step 3. Safe Senders will not help with these.
Step 2: Add Mobile Message to your Safe Senders
Adding both of these domains to your Safe Senders list tells Outlook not to junk mail from them:
mobilemessage.com.ausms.mobilemessage.com.au
Microsoft's instructions are here: Add recipients to the Safe Senders list in Outlook.
Add the domains rather than individual addresses, since every person who texts you has a different sender address. Each person who receives the notifications needs to do this for their own mailbox.
For most customers this is enough, and notifications start arriving straight away. It only works for mail Microsoft is junking, though. Microsoft ignores Safe Senders for anything it has classed as phishing, and ignores domain entries for anything it is quarantining rather than junking, so if the emails are being quarantined move on to Step 3.
Step 3: Ask your IT administrator to submit the messages as safe
When Microsoft quarantines the emails as High confidence phish, no allow list, safe-sender list or mail-flow rule will release them. Microsoft always quarantines that verdict. The only setting that overrides it is an allow entry created by an administrator through the Submissions page in the Microsoft Defender portal. Here is how:
- Go to security.microsoft.com/reportsubmission and choose the Emails tab.
- Choose Submit to Microsoft for analysis and pick one of the quarantined Mobile Message notifications (you can search by the sender address, which ends in
@sms.mobilemessage.com.au). - Select I've confirmed it's clean, then tick Allow this message and submit.
- Repeat for a few of the held messages from different senders. Each submission reports the false positive to Microsoft and helps stop the filter from flagging these emails in the first place.
That creates an entry in the Tenant Allow/Block List that is rated to override high confidence phishing, and it renews itself for as long as the notifications keep arriving. Microsoft's own steps are here: Report good email to Microsoft.
If the quarantine reason or the message's Detection technology says Impersonation, the administrator should instead open Email & collaboration > Policies & rules > Threat policies > Anti-phishing, select the policy that applies to your users, and add mobilemessage.com.au under Trusted senders and domains in the Impersonation section. This section is available on plans that include Microsoft Defender for Office 365.
Either change applies to everyone in the organisation, so individual users do not need to repeat Step 2. Release any notifications still sitting in quarantine once it is done.
While you wait
Nothing is lost. Every inbound SMS is in the Messenger, and if you use the Inbound Automations page you can also forward messages to a webhook or to another mobile number as a backup. See Inbound Automations.
If you have completed all three steps and notifications are still not arriving, contact us through live chat or by email and include the mailbox address that should be receiving them.