Email Security

Email Security

Marshall University Information Technology uses Microsoft Defender for Office 365, a comprehensive email security solution that helps protect users from a wide range of cyber threats. In addition to antivirus and anti-spam filtering, this service enhances the security of both incoming and outgoing messages, providing advanced protection against phishing, business email compromise, and ransomware. This ensures a safer email environment for students, faculty, and staff.

Key Benefits:

  • Review quarantined messages: Periodic notifications provide a summary of messages flagged as spam or suspicious. These notifications include options to review, release, or block messages, helping ensure legitimate emails are not missed.
  • Manage approved senders: Adjust your settings to allow messages from trusted senders, reducing the likelihood that important emails are incorrectly flagged as spam in the future.
  • Protect your inbox from common threats:
    • Unwanted bulk or mass mailings (spam)
    • Malicious attachments containing viruses or ransomware
    • Suspicious links designed to steal information or install harmful software (phishing)

Phishing Scams

According to the National Institute of Standards and Technology (NIST), phishing is a technique used to trick individuals into disclosing sensitive personal information through deceptive, computer-based means. [csrc.nist.gov]

The Federal Trade Commission (FTC), the nation’s consumer protection agency, explains that phishers often send emails or pop-up messages that appear to come from a legitimate organization—such as an Internet service provider (ISP), bank, online payment service, or government agency. These messages may ask you to “update,” “validate,” or “confirm” your account information. [ftc.gov]

Some phishing messages create a sense of urgency or threaten negative consequences if you do not respond. They often direct you to a website that looks legitimate but is actually fraudulent. The purpose of these fake sites is to trick you into providing personal information, which can then be used to commit identity theft or other forms of fraud.

Frequently Asked Questions

No action is required. Simply watch for Spam Notifications sent from quarantine@messaging.microsoft.com.

 

You may receive periodic emails notifying you of messages in quarantine. If you do not receive a notification, it means there are currently no messages in your quarantine.

Spam Notifications are sent from quarantine@messaging.microsoft.com with the subject line:
Spam Notification: [#] New Messages

 

Below is an example of what a notification looks like in Microsoft Outlook:

Spam notifications are sent at most once per day. To review messages, click Review in the notification email.

 

This will open your browser and direct you to the Microsoft Security portal:
View Quarantine Portal

Sign in using your MUNet credentials to view messages from the past 30 days.

Only select Release if you are confident the message is safe. Releasing a message delivers it to your inbox.

Once logged in, you can:

  • Preview Message to safely view its contents
  • Release message to deliver it to your inbox
  • View message header for technical delivery details
  • Delete from quarantine to permanently remove it

Quarantined messages are retained for 30 days. After that period, they are permanently deleted and no longer accessible.

Blocked messages are not accessible to users.

 

If you believe a legitimate message was blocked, contact the IT Service Desk at
itservicedesk@marshall.edu or 304-696-3200. Be prepared to provide the sender, date/time, and any relevant details.

Quarantined messages are held for review. You will receive a notification and can choose to release them if safe.

 

Blocked messages are automatically rejected and never delivered. You will not receive notifications for blocked messages, as many are filtered daily to prevent unnecessary alerts.

Messages are blocked when Microsoft Defender identifies them as high-risk or clearly unwanted.

No. Spam notification frequency is managed centrally and cannot be adjusted.

 

If you are receiving notifications more than once per day, please contact the IT Service Desk.

Yes. Outbound email—especially messages sent to external (non-Marshall) addresses—is scanned for suspicious or fraudulent activity.

 

This helps identify compromised accounts and prevent the spread of malicious email. If unusual activity is detected, MUIT is alerted.

Phishing (fraudulent email): Attempts to trick you into revealing sensitive information or taking harmful actions. These messages often impersonate trusted sources or ask you to click malicious links.

 

Spam (junk email): Unsolicited messages, typically for advertising. While annoying, spam is generally less harmful than phishing.

Understanding the difference helps ensure messages are reported correctly.

Before reporting, review the differences between phishing and spam in the section above.

 

To report a message in Outlook on the web:

  • Select the message
  • Click the ellipsis ()
  • Choose Report Message > Junk or Report Message > Phishing

What happens next:

  • Phishing reports are sent to the MU Information Security team for analysis and protection improvements
  • Junk reports are shared with Microsoft to improve filtering. The sender is also added to your blocked list

To securely encrypt and send email using your University account, please refer to our Knowledge Base for step-by-step instructions.