Knowledge Centre
Cyber Security GuidesChecklist and Guide

Missing Email Investigation Checklist

10 minutes to completeEvergreen guide — kept up to date

An expected email may be in Junk, quarantine, another folder or a different mailbox. It may also have been rejected, moved by a rule or never successfully sent. Use this checklist to identify what happened before changing spam or phishing protection.

An expected email may be in Junk, quarantine, another folder or a different mailbox. It may also have been rejected, moved by a rule or never successfully sent. Use this checklist to identify what happened before changing spam or phishing protection.

Before you begin

A screenshot of Sent Items is useful context, but it is not proof that the recipient’s service accepted the message. Collect delivery evidence from the sender’s logs or ask for the message ID and any non-delivery report.

Step 1 — Collect the details

  • □ Exact sender address
  • □ Exact recipient address
  • □ Date sent
  • □ Approximate time and time zone
  • □ Subject line
  • □ Attachment name (if applicable)
  • □ Message ID (if available from sender logs or headers)
  • □ Non-delivery report (if received by sender)
  • □ Sending platform or service

Step 2 — Check the mailbox

  • □ Search all folders by sender address, subject and approximate date
  • □ Check Junk or Spam — use “Not junk” or “Not spam” rather than simply moving it
  • □ Check quarantine through the approved portal or notification
  • □ Check Deleted Items
  • □ Check Archive
  • □ Check Focused Inbox, Other, Gmail tabs or categories
  • □ Check shared mailboxes
  • □ Check blocked-sender list
  • □ Review inbox rules for unfamiliar or unexpected entries
  • □ Review forwarding rules

Step 3 — Confirm the sender

  • □ Message left the Outbox (not stuck in Drafts or Outbox)
  • □ Recipient address is correct
  • □ No non-delivery report was received
  • □ Sender has checked their sending logs
  • □ Attachment is within size and type limits
  • □ Sending account does not show signs of compromise
  • □ Sending service or platform is recognised and current
  • □ Domain authentication (SPF, DKIM, DMARC) is configured and passing

Step 4 — Trace the message

  • □ Receiving service found the message in its logs
  • □ Gateway or security service identified
  • □ Delivery status identified (delivered, quarantined, rejected, deferred)
  • □ Security verdict identified
  • □ Applied policy identified
  • □ Delivery location identified
  • □ Rejection reason recorded if applicable
  • □ User or administrator action recorded if applicable

Step 5 — Classify the cause

  • □ Delivered normally (check other mailbox locations)
  • □ Junk or Spam classification
  • □ Quarantine
  • □ Spam false positive
  • □ Bulk-mail classification
  • □ Phishing detection
  • □ Impersonation detection
  • □ Malware or attachment block
  • □ Inbox rule
  • □ Mail-flow or transport rule
  • □ Third-party gateway decision
  • □ Authentication failure (SPF, DKIM or DMARC)
  • □ Sending-reputation issue
  • □ Incorrect recipient address
  • □ Message-size or attachment-type issue
  • □ Not received by organisation
  • □ Not successfully sent

Step 6 — Correct the cause

  • □ Report as not junk or not spam using the platform’s built-in tool
  • □ Submit false positive through the platform’s approved submission process
  • □ Ask sender to correct authentication (SPF, DKIM, DMARC)
  • □ Ask sender to correct sending address or platform
  • □ Ask sender to correct routing or sending infrastructure
  • □ Remove incorrect inbox rule
  • □ Amend incorrect mail-flow or transport rule
  • □ Review attachment or URL if flagged by security scanning
  • □ Correct gateway policy where applicable
  • □ Create targeted exception (see Step 7 before proceeding)
  • □ Escalate if supplier compromise is suspected

Step 7 — Review any exception

If a correction requires an exception, confirm all of the following before creating it:

  • □ Specific, documented business reason
  • □ Narrow sender scope (specific address or authenticated domain — not a whole domain without authentication check)
  • □ Narrow recipient scope (specific user or group)
  • □ Sender authentication verified
  • □ Named owner assigned
  • □ Approval recorded
  • □ Expiry date set
  • □ Monitoring enabled for matched messages
  • □ Review date scheduled

Do not create an organisation-wide bypass to solve one unexplained message. If you cannot identify the exact cause, escalate before creating any exception.

Step 8 — Confirm the result

  • □ Test message received correctly
  • □ Normal message from sender received correctly
  • □ Sender authentication passes
  • □ Expected attachment delivered
  • □ Quarantine behaviour is correct and unchanged for other senders
  • □ No broad protection has been disabled
  • □ Delivery logs reviewed to confirm expected outcome
  • □ User has been informed of the resolution
  • □ Incident and corrective action recorded
CauseWho can usually fix itAppropriate action
Junk / Spam false positiveRecipient or administratorReport as not junk; submit false positive
Quarantine — spam or bulkRecipient (if permitted) or administratorRelease and report; investigate why it was caught
Quarantine — phishing / malwareAdministrator onlyInvestigate carefully before releasing; contact sender
Inbox ruleRecipient or administratorRemove or amend the offending rule
Mail-flow ruleAdministratorAmend or remove the rule; document the change
Authentication failureSender’s IT teamCorrect SPF, DKIM or DMARC records
Gateway holdAdministrator with gateway accessReview gateway policy; correct or create narrow exception
Rejected deliverySender or bothResolve the rejection reason; sender may need to correct sending infrastructure

Want the full explanation?

Read our Technology Intelligence article for a plain-English explanation of why email gets filtered, the difference between Junk and quarantine, and why broad allow-listing can introduce new risks.

Missing Important Emails? Do Not Just Weaken the Spam Filter

Plain-English Takeaway

Do not weaken the spam filter simply because an important email appears to be missing. Check the mailbox, quarantine, rules and delivery logs first. Identify the exact cause, correct the sender or policy where possible and use only a narrow, documented exception when one is genuinely required.

Downloadable guide

Download the Missing Email Investigation Checklist

A printable checklist for tracing missing legitimate email and correcting delivery without unnecessarily weakening security.

Download PDF

Free download. No email address required.

Want the full business explanation?

The Technology Intelligence article covers why this matters, where it helps and what to watch out for.

Read the full Technology Intelligence article

Related Knowledge Centre resources

DMARC: Three Questions to Ask Your IT Provider

Check whether your business email domain is protected against spoofing and impersonation.

Coming Soon

WhatsApp Impersonation and Payment Fraud Checklist

Checks to help staff spot fake WhatsApp accounts and verify payment requests safely.

Coming Soon

Browser Extension Security Audit

Identify installed browser extensions, review their permissions and decide which should be approved, restricted or removed from business browsers.

View guide

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.