An email was quarantined by Iconium Email Threat Protection
How to read your quarantine digest, release a legitimate message, and tell the difference between a real quarantine notice and a fake one.
- quarantine
- spam
- email security
- digest
On this page
Iconium Email Threat Protection sits in front of your mailbox and holds anything that looks like spam, phishing, or malware before it reaches you. Held messages go to quarantine rather than being deleted, so nothing legitimate is lost — it just needs releasing.
Your quarantine digest
You receive a digest listing what was held. Each entry shows the sender, the subject, and the time it arrived, with an option to release it.
To release a message you were expecting:
- Open the digest and find the message.
- Check the sender address carefully — the full address, not just the display name.
- Choose the release option next to that message.
- It is delivered to your inbox within a few minutes. If it does not arrive within fifteen, tell us.
Releasing does not always mean future messages get through. If it is a sender you deal with regularly, ask us to allow them properly rather than releasing every time.
Before you release anything, look twice
Quarantine exists because something about the message was suspicious. The system is not always right, but it is right often enough that a moment’s thought is worth it.
Ask yourself:
- Was I expecting this? An unexpected invoice, delivery notice, or voicemail attachment is the classic pattern.
- Does the sender’s full address match the company?
accounts@microsoft-billing-secure.comis not Microsoft. - Is it a first-time sender asking for something urgent? Payment, credentials, gift cards, a “quick favour” from an executive.
- Does the subject reference a thread I do not recognise?
If any of those give you pause, do not release it. Forward the digest entry to us, or call — we will look at the message safely and tell you what it is. That takes us two minutes and costs you nothing.
Watch out for fake quarantine notices
This is one of the most successful phishing tactics we see, precisely because people are used to receiving real digests.
A genuine notice from us:
- Comes from the address we told you about when the service was set up.
- Lists specific messages with real senders and subjects you can evaluate.
- Never asks you to sign in with your Microsoft password to release mail.
That last point is the one that matters. If clicking release takes you to a page asking for your email password, close it immediately and call us. No legitimate quarantine release requires you to re-enter your Microsoft 365 credentials.
If you already entered your password on such a page, go straight to Suspicious sign-in alert, or you think your account was compromised and call us now.
A message you needed never arrived and is not in the digest
- Check your Junk Email folder in Outlook. Quarantine and Junk are two different places — mail can be delivered but filtered locally.
- Check Deleted Items, and search your whole mailbox for the sender’s domain.
- Ask the sender for the exact time they sent it and the exact address they sent from. We can trace a message with those two details in minutes; without them it is guesswork.
- Ask whether they received a bounce message, and if so, what it said. The wording is diagnostic.
Then contact us with those details and we will trace where it went.
Mail you keep receiving that should be blocked
Marketing you subscribed to is best dealt with by unsubscribing — that is genuine and works. For anything malicious, forward it to us rather than just deleting it, so we can tighten the filtering for everyone at your company rather than only for you.
Not sure about a message? Call 440-991-9980 or email support@iconiumnetworks.com. Forwarding us something suspicious is always the right call — we would far rather look at ten harmless newsletters than miss the one that mattered.
Did this fix the problem?
If you followed these steps and it's still not working, get in touch and mention this article — An email was quarantined by Iconium Email Threat Protection — so we can skip the basics.