Missing Email Investigation Checklist
An expected email may be in Junk, quarantine, another folder or a different mailbox. It may also have been rejected, moved by a rule or never successfully sent. Use this checklist to identify what happened before changing spam or phishing protection.
An expected email may be in Junk, quarantine, another folder or a different mailbox. It may also have been rejected, moved by a rule or never successfully sent. Use this checklist to identify what happened before changing spam or phishing protection.
Before you begin
A screenshot of Sent Items is useful context, but it is not proof that the recipient’s service accepted the message. Collect delivery evidence from the sender’s logs or ask for the message ID and any non-delivery report.
Step 1 — Collect the details
- □ Exact sender address
- □ Exact recipient address
- □ Date sent
- □ Approximate time and time zone
- □ Subject line
- □ Attachment name (if applicable)
- □ Message ID (if available from sender logs or headers)
- □ Non-delivery report (if received by sender)
- □ Sending platform or service
Step 2 — Check the mailbox
- □ Search all folders by sender address, subject and approximate date
- □ Check Junk or Spam — use “Not junk” or “Not spam” rather than simply moving it
- □ Check quarantine through the approved portal or notification
- □ Check Deleted Items
- □ Check Archive
- □ Check Focused Inbox, Other, Gmail tabs or categories
- □ Check shared mailboxes
- □ Check blocked-sender list
- □ Review inbox rules for unfamiliar or unexpected entries
- □ Review forwarding rules
Step 3 — Confirm the sender
- □ Message left the Outbox (not stuck in Drafts or Outbox)
- □ Recipient address is correct
- □ No non-delivery report was received
- □ Sender has checked their sending logs
- □ Attachment is within size and type limits
- □ Sending account does not show signs of compromise
- □ Sending service or platform is recognised and current
- □ Domain authentication (SPF, DKIM, DMARC) is configured and passing
Step 4 — Trace the message
- □ Receiving service found the message in its logs
- □ Gateway or security service identified
- □ Delivery status identified (delivered, quarantined, rejected, deferred)
- □ Security verdict identified
- □ Applied policy identified
- □ Delivery location identified
- □ Rejection reason recorded if applicable
- □ User or administrator action recorded if applicable
Step 5 — Classify the cause
- □ Delivered normally (check other mailbox locations)
- □ Junk or Spam classification
- □ Quarantine
- □ Spam false positive
- □ Bulk-mail classification
- □ Phishing detection
- □ Impersonation detection
- □ Malware or attachment block
- □ Inbox rule
- □ Mail-flow or transport rule
- □ Third-party gateway decision
- □ Authentication failure (SPF, DKIM or DMARC)
- □ Sending-reputation issue
- □ Incorrect recipient address
- □ Message-size or attachment-type issue
- □ Not received by organisation
- □ Not successfully sent
Step 6 — Correct the cause
- □ Report as not junk or not spam using the platform’s built-in tool
- □ Submit false positive through the platform’s approved submission process
- □ Ask sender to correct authentication (SPF, DKIM, DMARC)
- □ Ask sender to correct sending address or platform
- □ Ask sender to correct routing or sending infrastructure
- □ Remove incorrect inbox rule
- □ Amend incorrect mail-flow or transport rule
- □ Review attachment or URL if flagged by security scanning
- □ Correct gateway policy where applicable
- □ Create targeted exception (see Step 7 before proceeding)
- □ Escalate if supplier compromise is suspected
Step 7 — Review any exception
If a correction requires an exception, confirm all of the following before creating it:
- □ Specific, documented business reason
- □ Narrow sender scope (specific address or authenticated domain — not a whole domain without authentication check)
- □ Narrow recipient scope (specific user or group)
- □ Sender authentication verified
- □ Named owner assigned
- □ Approval recorded
- □ Expiry date set
- □ Monitoring enabled for matched messages
- □ Review date scheduled
Do not create an organisation-wide bypass to solve one unexplained message. If you cannot identify the exact cause, escalate before creating any exception.
Step 8 — Confirm the result
- □ Test message received correctly
- □ Normal message from sender received correctly
- □ Sender authentication passes
- □ Expected attachment delivered
- □ Quarantine behaviour is correct and unchanged for other senders
- □ No broad protection has been disabled
- □ Delivery logs reviewed to confirm expected outcome
- □ User has been informed of the resolution
- □ Incident and corrective action recorded
| Cause | Who can usually fix it | Appropriate action |
|---|---|---|
| Junk / Spam false positive | Recipient or administrator | Report as not junk; submit false positive |
| Quarantine — spam or bulk | Recipient (if permitted) or administrator | Release and report; investigate why it was caught |
| Quarantine — phishing / malware | Administrator only | Investigate carefully before releasing; contact sender |
| Inbox rule | Recipient or administrator | Remove or amend the offending rule |
| Mail-flow rule | Administrator | Amend or remove the rule; document the change |
| Authentication failure | Sender’s IT team | Correct SPF, DKIM or DMARC records |
| Gateway hold | Administrator with gateway access | Review gateway policy; correct or create narrow exception |
| Rejected delivery | Sender or both | Resolve the rejection reason; sender may need to correct sending infrastructure |
Want the full explanation?
Read our Technology Intelligence article for a plain-English explanation of why email gets filtered, the difference between Junk and quarantine, and why broad allow-listing can introduce new risks.
Missing Important Emails? Do Not Just Weaken the Spam Filter →
Plain-English Takeaway
Do not weaken the spam filter simply because an important email appears to be missing. Check the mailbox, quarantine, rules and delivery logs first. Identify the exact cause, correct the sender or policy where possible and use only a narrow, documented exception when one is genuinely required.
Downloadable guide
Download the Missing Email Investigation Checklist
A printable checklist for tracing missing legitimate email and correcting delivery without unnecessarily weakening security.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
DMARC: Three Questions to Ask Your IT Provider
Check whether your business email domain is protected against spoofing and impersonation.
Coming SoonWhatsApp Impersonation and Payment Fraud Checklist
Checks to help staff spot fake WhatsApp accounts and verify payment requests safely.
Coming SoonBrowser Extension Security Audit
Identify installed browser extensions, review their permissions and decide which should be approved, restricted or removed from business browsers.
View guide