Category: Microsoft 365 Administration · View source ↗
Microsoft 365 Administration
Mail Trace Investigation
Run a disciplined Exchange Online message trace — tight timeframe, sender/recipient pair, verdict reading, and the extended (historical) trace path for anything older than 10 days. Use when a ticket needs proof of what happened to a specific message or mail between two parties.
Connectors: none — works with Thread out of the box
Role: Technician
Outcome: Faster Resolution & Response
When to use: A ticket needs proof of what happened to a specific message — “did <sender>‘s email to <recipient> ever arrive,” “prove we sent it” / “prove they sent it” disputes, checking whether a batch of messages was quarantined/dropped/delivered, or feeding evidence into a delivery diagnosis (mail-flow-delivery owns the broader NDR/bounce playbook; this skill owns the trace mechanics). The agent frames the trace parameters and reads the results the tech pastes back; the tech runs the trace in the Exchange admin center or Defender portal. Read-only — this skill never changes the tenant.
Run it: on one message or sender/recipient pair — you frame the parameters and read the results, a technician runs the trace (not a Flow: it needs a human at the console).
Was this page helpful?
⌘I