A quarantine folder is a holding area for email a filter judged dangerous or unwanted, kept back instead of delivered. The message sits somewhere other than your inbox and your junk folder, and it’s still intact. It’s in a separate store belonging to whatever filters your mail, waiting for somebody to release it or for a clock to run out.
- The word folder is why people can’t find it. In most business setups quarantine lives on the filtering service, and you reach it through a different web page. That’s why searching Outlook or Gmail for it turns up nothing.
- Quarantine and the junk folder are two destinations for the same suspicion. Junk mail reached you and got filed out of the way. Quarantined mail stopped short of your mailbox. Which one a message gets is a setting somebody in your organization chose.
- Everything in there is on a timer, and the timer ends in deletion rather than in archiving. Microsoft’s default for spam is fifteen days and Google’s admin quarantine is thirty.
- You can release some of it yourself. The rest belongs to an administrator. The split follows how dangerous the filter thought the message was rather than how much you want it.
Why you cannot find the folder
Most people arrive at this question holding a specific problem. A client says they sent something. It’s missing from the inbox, it’s missing from junk, and somebody has said the word quarantine. So you go looking through the mail app for a folder with that name. In the ordinary business case, your search is sound and the folder is the fiction.
In Microsoft 365 and Google Workspace, quarantine is a store held by the filtering service. The messages in it were stopped on the way, before anything was written into your mailbox. Microsoft’s documentation is plain about where it lives. Quarantined mail is viewed in the Microsoft Defender portal at security.microsoft.com, on a page called Quarantine. That page sits somewhere different from the mailbox entirely (checked September 5, 2026). Google’s version is further away still. Its Gmail quarantine is part of an administrator tool, and “access to this quarantine is limited to super admins and admins that have been assigned the Access Admin Quarantine Gmail privilege” (checked September 5, 2026). It opens for administrators only.
Three arrangements share the name, which is worth knowing before you go hunting.
A store on the filtering service, reached through a web console. This is the common one, and it’s what both of the big platforms mean.
A designated mailbox, where a rule redirects suspect mail to one address that somebody in the firm watches. Older gateways do this. It’s the arrangement that produces an actual folder, in somebody else’s mailbox rather than in yours.
A real folder in your mailbox, created by a gateway that files suspect mail rather than holding it back. This is the rarest of the three now, and the reason the phrase quarantine folder survives at all.
So the first useful thing to settle is which of those your firm has. It decides whether the answer to “where is my email” is a page, a person, or a folder you already have access to.
Forty days off Venice, and the three things the word kept
The word arrives in English in the 1660s. Etymonline has it from Italian quaranta giorni, “space of forty days”, and explains the number: “So called from the Venetian policy (1377) of keeping ships from plague-stricken countries waiting off its port for 40 days to assure that no latent cases were aboard.” There is an older English sense, from the 1520s, for the forty days a widow was entitled to stay in her dead husband’s house, which is a reminder that the word began as a protected span of time rather than as a punishment.
Three features of that Venetian arrangement came across into software, and each one explains something people find surprising about email quarantine.
Suspicion rather than proof. A ship was held for where it had come from. The port acted on its origin alone, with the crew unexamined and the plague unproven. A quarantined message has exactly that standing. It matched a pattern, and that’s the whole of what anyone knows about it. A great deal of what sits in quarantine is a newsletter, a first message from a supplier, or a client whose mail server is misconfigured.
Separation rather than destruction. The cargo was held apart from the city, intact, and most of it was eventually landed. Quarantine is the gentlest thing a filter can do short of delivering the message. It’s chosen precisely because deleting a suspicious message outright would lose the ones that were fine.
A fixed term. Forty days, and then the matter was settled one way or the other. Every quarantine in software has kept the clock. It’s the property that catches people out, because the modern version ends in deletion rather than in release.
Hold those three together and you have the whole shape of the thing. A quarantined message is presumed doubtful rather than guilty. It’s being kept rather than destroyed. And it’s being kept for a stated number of days.
Quarantine and the junk folder are not the same place
This is the distinction that does the most work, and hardly anybody is told it.
Your junk or spam folder is part of your mailbox. The message was delivered, your mail system judged it unwanted, and it was filed somewhere out of the way. You own it. It syncs to your phone. You can search it and drag a message out of it, and moving one back to the inbox teaches the filter something.
Quarantine sits upstream of all that. The message was stopped before delivery, and it belongs to the filtering service rather than to you. It lives outside your mail app’s search, off your phone, and clear of your storage. Getting it out is a request rather than a drag.
The two are alternatives, and the choice between them is a policy setting rather than a property of the message. Microsoft says so directly. Its documentation notes that administrators “can reduce quarantined messages by changing actions to deliver messages to the Junk Email folder instead of quarantine in anti-spam policies and anti-phishing policies”. It runs the other way too, with policies modified “to quarantine messages instead of delivering them to the Junk Email folder” (checked September 5, 2026). The same spam verdict, two destinations, decided by whoever configured the tenant.
One line on the same page is worth reading twice by anybody who thinks quarantine is optional: “You can’t completely turn off quarantine in Microsoft 365. Malware and high-confidence phishing messages are always quarantined to protect the service” (checked September 5, 2026). Some categories are held whatever the policy says, because the platform keeps them out of a mailbox altogether.
For a small firm the practical consequence is about where to look when something is missing. Junk is the first place, one click away. Quarantine is the second, and it’s somewhere else. If the firm has never set up notifications, the message sits there unannounced. That silence is what turns a filter into a problem, and it’s the same failure shape as mail that goes missing by being quietly filed.
What actually put the message there
Quarantine is a destination that several quite different judgments end at. Microsoft’s own list of quarantine reasons is a fair map of the field, because most filtering products draw the same distinctions under different names (checked September 5, 2026).
Spam and high confidence spam. Ordinary unwanted commercial mail, and the same judgment made with more certainty.
Bulk. Mail sent to a list rather than to a person, which is a separate axis from spam. Legitimate newsletters land here constantly. It’s the commonest reason an expected message goes missing.
Phishing and high confidence phishing. A message the filter reads as an attempt to get a credential or a payment. The high-confidence version is treated far more severely, and the difference matters to you because it decides who’s allowed to release it.
Malware. An attachment the scanner recognizes, or one caught by a rule about file types. Microsoft notes that a common attachments filter can treat a file as malware “based solely on the file extension using true type matching”, which is how an ordinary archive from a client gets stopped with everything inside it perfectly fine (checked September 5, 2026).
Impersonation and spoofing. The message claims to be from a person or a domain, and the authentication tells a different story. This is the category that catches your own firm’s mail when it’s sent through a third party. The fix is at the sending end rather than in the quarantine.
A rule somebody wrote. In Microsoft’s world these are mail flow rules, historically transport rules, and they quarantine on whatever grounds the firm chose. This one is worth separating from the rest because detection played no part in it. Somebody made a decision in advance, and the reason is written down in the rule rather than in the message.
An attachment that could not be examined. A password-protected file is closed to the scanner, so some setups hold the message rather than guess. Microsoft calls this a “Password protected item” and lets the recipient supply the password so the file can be rescanned (checked September 5, 2026).
Knowing which of these applies tells you how likely a mistake is. A bulk verdict on a trade newsletter is a matter of taste. A malware verdict on an attachment is a claim about a file. A transport-rule verdict is a claim about your firm’s own policy, so the conversation you want is with whoever owns the rule rather than with the filter.
Who is allowed to let it out
The buttons change depending on the message, and that’s the part that confuses people most. A grayed-out button is the design working as intended. It’s telling you this one belongs to an administrator.
Microsoft publishes the default permissions as a table, and the pattern in it is easy to state (checked September 5, 2026). A recipient can normally view, release and delete their own messages quarantined as spam, high confidence spam, bulk, phishing, spoofing or impersonation. Messages quarantined as malware, as high confidence phishing, or by a mail flow rule stay with an administrator. Microsoft is explicit that recipients cannot release those “regardless of how the quarantine policy is configured”.
Where the recipient is blocked, there’s usually a second action rather than a dead end. Requesting release puts the message in front of an administrator, who approves it or denies it. The message stays where it is in the meantime. Microsoft describes the request landing with the tenant’s admins through an alert policy, so somebody is meant to be watching. How quickly they watch is a question about your firm rather than about the software.
Two details about release surprise people. Both are worth knowing before you promise a client you’ve found their email.
The first is that releasing is a re-delivery rather than a restoration. Microsoft’s wording: “Releasing a message from quarantine re-delivers it to your mailbox rather than restoring it in place. As a result, the message appears in Outlook with the re-delivery time as the delivery timestamp instead of the original delivery time. The original send date is preserved in the message headers” (checked September 5, 2026). So a message sent last Tuesday arrives at the top of today’s inbox with today’s time on it. Sort by date and it sits among today’s mail. The real timestamp is in the headers.
The second is that everything done to a quarantined message is recorded. Microsoft states that “all actions taken by admins or users on quarantined messages are audited” (checked September 5, 2026). For a practice holding client financial affairs, that’s a point in the arrangement’s favor. Releasing something is a decision with a name attached to it.
Google’s arrangement puts the whole thing further from the recipient. Only administrators, or a designated reviewers group, see the quarantine at all, and Google says flatly that “recipients are never notified when a message is quarantined” (checked September 5, 2026). In a Workspace firm, a quarantined message stays invisible to the person it was addressed to until somebody with the privilege goes and looks.
The clock nobody mentions
Quarantine is a waiting room with a fixed lease. When the lease ends the message is deleted rather than archived.
Microsoft’s retention values differ by why the message was held, which is a detail worth having exactly right (checked September 5, 2026):
- Messages quarantined by anti-spam policies as spam, high confidence spam, phishing, high confidence phishing or bulk are kept 15 days under the default anti-spam policy and under custom anti-spam policies, and 30 days under the Standard and Strict preset security policies. You can set the value anywhere from 1 to 30 days in the default and custom policies. The presets hold it fixed.
- Messages quarantined by anti-malware policies, by mail flow rules, and by Safe Attachments are kept 30 days, and that value is fixed too.
Then the sentence that matters more than any of the numbers: “When messages expire from quarantine after the retention period, the messages are permanently deleted and can’t be recovered.”
Google’s is simpler and equally final. “Quarantined messages are stored in quarantine up to 30 days after sending. Messages are automatically and permanently deleted after 30 days” (checked September 5, 2026).
For a small firm this is the whole risk in one paragraph. A quarantine nobody reviews is a shredder on a timer, and the default lease on the most common category is two weeks. During a filing season, two weeks is one busy stretch, the kind where the only things anybody looks at are the things they were chased about. Think of the engagement letter that went to quarantine because the client’s new practice-management system sends on their behalf. It has a date on it, and the date keeps moving toward you while you file.
Which is the argument for the notification, and for reading it.
The notification, and the fake one
Because quarantine is somewhere you’d never think to look, the platforms send a summary of what’s in it. Microsoft calls this a quarantine notification, and older documents and half the industry still call it a spam digest or an end-user digest.
Two facts about it are worth pinning down (checked September 5, 2026). Its frequency is a setting, offered as every four hours, daily or weekly. And whether it arrives at all depends on the policy. Notifications are off in the default quarantine policies named AdminOnlyAccessPolicy and DefaultFullAccessPolicy, and on in the policy used by the preset security policies. If nobody in your firm has ever received one, that’s a configuration rather than a sign of an empty quarantine.
The notification itself is a short list of held messages. Each line carries a sender, a subject and the date it was quarantined. The buttons depend on the verdict: review the message, release it, request its release, block the sender.
Here’s the thing to be careful about. This is now one of the most impersonated emails in business. A message that says some of your mail is being held, with a familiar logo and a button, is exactly the shape of a credential-harvesting attack, and attackers know it.
McMaster University’s information security office published an advisory on a campaign of precisely this kind on October 23, 2025. It describes mail that poses as “a legitimate quarantine notification, claiming to inform the recipient about emails caught by the McMaster quarantine system”. The message “prompts the recipient to click a link, which redirects to a fraudulent Microsoft login page designed to steal credentials” (checked September 5, 2026). Similar campaigns have been documented repeatedly since.
The lure works because the real thing is unfamiliar. Hardly anybody sees enough genuine quarantine notifications to know what one looks like, and everybody understands the anxiety of held mail. Two habits take most of the risk out of it, and both are plain enough to keep. Reach the quarantine page by an address you keep yourself, rather than by a button in a message, and the fake version is harmless. And treat a sign-in prompt that follows a link in an email as suspect, because a genuine quarantine page in Microsoft 365 or Google Workspace meets a session you already have.
The same instinct applies one step further in. Microsoft’s own guidance on releasing a password-protected attachment warns against entering an account password, a banking password or other unrelated credentials in the release view. Supply the attachment password only when the message was expected and you can validate the sender (checked September 5, 2026). Quarantine is a place where people are already braced to type something, which is why it attracts this kind of attention.
Quarantine outside the mailbox
If you arrived here from an antivirus warning rather than from a missing email, the word means something adjacent and behaves differently in one important way.
In endpoint security, quarantining a file moves it somewhere it cannot run. Microsoft’s own description is compact: “Quarantine moves the file to a safe location and blocks it so it can’t run”, and “a quarantined file does not pose any risk to your PC” (checked September 5, 2026). Windows Security keeps these under protection history as quarantined items, and restoring one puts it back where it came from.
The important difference is the clock. Microsoft says of quarantined files that “you can leave a file in quarantine for as long as you like” (checked September 5, 2026). A quarantined file waits indefinitely. A quarantined email waits out its lease and then goes. Two systems, one word, opposite defaults, and the habit people carry over from the first is what makes them relaxed about the second.
Two other senses turn up often enough to name. macOS attaches a quarantine flag to files arriving from the internet, which is what triggers the check the first time you open a downloaded application. The flag is a note on the file rather than a place, and the file stays where you put it. And in software development, a quarantined test is one moved out of the main suite because it fails unpredictably, which borrows the isolation idea and none of the danger. If either of those is what you were looking for, the mail sense on this page will not help you.
The other quarantine, the one that protects the software
A newer sense has appeared in AI mail products, and it’s genuinely a different thing wearing the same word. The two answer different questions, and a product page will rarely tell you which one it means. So it’s worth separating clearly.
A security quarantine protects the reader from the message. The filter thinks the message might harm you, so it’s held until you decide.
The newer kind protects the software from the message. When a mail client has an assistant reading everything that arrives, prose starts doing a second job. To a system that follows written instructions, a message is a set of instructions. A stranger who can get text in front of it can try to address it directly. Three screens down a plausible invoice, one line can be addressed to the assistant instead of to you. Holding unvouched mail away from the model is the response, and what an AI mail client can and cannot see works through why the boundary sits where it does and what it costs.
Three things follow, and they are the questions worth asking any vendor who uses the word.
It says the assistant has left the message alone. That’s the whole of the claim. Whether the message is a scam is a separate question, and a product that implies otherwise is claiming something it hasn’t built. The spam and phishing filtering in front of your mailbox is doing that other job, and it carries on doing it.
The trigger is usually the sender rather than the content. Content-based detection finds the obvious cases. The durable version of this control is about standing: has this address written to you before, and has anything vouched for it. That makes it a relative of the safe-sender list rather than of the spam filter, and it inherits that instrument’s blind spot, which what a VIP contact is sets out at length.
What “held” means varies enormously. Held from the assistant but still in your inbox is one thing. Held from you as well is another. Three separate questions sit inside the word. Is the message visible to you at all? Is it ranked? Can it be read safely without being processed? Those are the ones to put to a vendor, and The questions worth settling before an AI touches client mail is the full list.
What Point holds back
Point is a mail client with an assistant reading your correspondence, so it runs a quarantine of the second kind. It sits alongside whatever filtering your Gmail or Microsoft 365 account already does rather than replacing it. Your existing quarantine, if your firm has one, carries on exactly as before.
Two things go to Point’s quarantine. Mail from an address with no history with you is held back before anything reads it, so a stranger stays outside the part of your inbox that acts on words. And mail built to manipulate whatever reads it is stopped before any processing happens, with the reason written on the card: pattern detection, injection risk. A held message sits untouched. It stays out of the summaries, the ranking, the tasks and the drafts. It waits in one place, labeled, with everything else Point has held.
Reviewing one opens a sealed, read-only view. You see the raw text, including any hidden instructions, so you can see what the message was attempting. Looking is safe, because the text sits there inert. Releasing returns a message to normal handling, which is the right outcome for a false positive. Leaving it where it is costs you nothing. You settle that rather than Point, and it’s the one place in the product where the software declines to have an opinion.
The narrow claim is the honest one, so it’s worth repeating. This is a locked room rather than a fraud check. It stops hostile prose reaching the part of the system that acts on prose. Whether an invoice is real is a question for something else.
Point’s reach is a separate control, and you set it action by action. The range runs from suggest-only through review to fully handled, and review is where it starts. Setting how much your inbox does on its own is the account of that, and what an autonomy setting is is the general term. Point keeps an ordered record of everything it did, and undo reaches back through it, which is the activity log. Everything else it does is on the benefits page. It runs on the mailbox you already have, so your mail stays put and your address stays yours.
When quarantine is not the thing to be looking at
People often arrive at quarantine because something went wrong, and in a fair number of those cases the problem lives somewhere else. Four patterns are common.
The same sender keeps being held. Releasing each message one at a time treats the symptom every time. A sender who lands in quarantine repeatedly is usually failing an authentication check at their end. That’s a conversation with them or with their IT provider rather than a job for your release button.
Legitimate mail is held often enough to be a workflow. If somebody in the firm reviews quarantine daily and rescues real client mail from it, the filter policy is set too tight for the practice. That’s an adjustment to how the filter is configured, and it belongs with whoever administers the tenant.
Nothing is being held, but things still go missing. Quarantine has a specific and narrow job. Mail that arrived, was delivered, and then sank under two hundred other messages went through delivery normally, so the quarantine page will be empty of it. That’s a triage problem, and how email triage works is the shape of the answer.
You want to know what an assistant has and has not read. That’s a question about processing rather than about delivery. The answer is a record of what the software did rather than a list of what a filter stopped.
There’s also the honest case for leaving well alone. If your firm’s quarantine is quiet, the notification arrives weekly, and the only thing in it for six months has been conference spam, then very little attention is the right amount to pay it. Keep the clock in view and you’ve done enough. Whatever is in there has a date on it, and after that date it’s gone for good.
Common questions
Where is the quarantine folder in Outlook or Gmail?
In a business Microsoft 365 or Google Workspace account, it lives outside the mail app entirely. Microsoft holds quarantined mail in the Microsoft Defender portal at security.microsoft.com, on a page called Quarantine, which is separate from Outlook. Google’s Gmail quarantine is part of the admin console and is limited to super admins and admins granted the Access Admin Quarantine Gmail privilege, so it stays closed to an ordinary user. If your firm uses a third-party filtering gateway instead, quarantine will be on that vendor’s website. In every case it’s somewhere other than the mailbox, which is why searching for a folder finds nothing.
What is the difference between quarantine and the junk email folder?
The junk folder is part of your mailbox. The message was delivered to you and filed out of the way, and you can search it, see it on your phone and drag a message back to the inbox. Quarantine sits upstream of delivery. The message stopped short of your mailbox, so it stays outside your search, off your phone, and out of your hands to move. Which destination a suspicious message gets is a policy choice made by whoever configured your mail filtering, and Microsoft’s documentation describes switching between the two as a setting on anti-spam and anti-phishing policies.
How long do emails stay in quarantine before they are deleted?
Long enough to be dangerous to forget. In Microsoft 365 the default is fifteen days for messages held by anti-spam policies, thirty days under the Standard and Strict preset security policies, and thirty days for malware, mail flow rules and Safe Attachments. Google’s admin quarantine keeps messages for up to thirty days. At the end of the period the message is permanently deleted, and it’s beyond recovery for everyone including your administrator. Quarantine is a waiting room with a lease rather than an archive.
Why did a normal email from a client end up in quarantine?
Usually one of three reasons, and all three leave the message itself perfectly fine. It was classed as bulk because it was sent through a mailing platform. It failed an authentication check because the client’s mail is sent on their behalf by a system that is not properly authorized to do so. Or your own firm has a rule that catches it, in which case detection played no part and the reason is written in the rule. Repeat offenders are worth fixing at the sending end rather than releasing one message at a time.
Can I release a quarantined message myself?
It depends on why it was held. By default a recipient can view and release their own messages quarantined as spam, bulk, phishing, spoofing or impersonation. Messages quarantined as malware, as high confidence phishing, or by a mail flow rule are administrator-only, and Microsoft states that recipients cannot release those whatever the quarantine policy says. Where you are blocked you can usually request release, which sends the decision to an administrator to approve or deny. Note that a released message arrives with the time of release as its delivery timestamp, so it appears at the top of the inbox rather than in its original place.
Is an email telling me I have messages in quarantine safe to click?
Treat it with care. Genuine quarantine notifications exist, and in Microsoft 365 they can be sent every four hours, daily or weekly. They are also one of the most copied formats in phishing, precisely because so few people have seen a real one. A university security office documented a campaign in October 2025 in which a convincing quarantine notice led to a fake Microsoft sign-in page built to harvest credentials. The safe habit is to reach the quarantine page by an address you keep yourself rather than by a button in a message, and to treat any sign-in prompt reached from an email link as suspect.
Does an AI email tool’s quarantine protect me from phishing?
By itself it protects the software, and the difference is worth being precise about. A quarantine in an AI mail client exists to keep mail from an unknown or hostile sender away from the model, so a stranger stays outside software that acts on instructions. That’s protection for the system rather than a verdict on whether an invoice is genuine. Your spam and phishing filtering is doing the other job and continues to. A vendor who blurs the two is describing a capability they have not built.
The short version
- A quarantine folder is a holding area for mail a filter judged dangerous or unwanted. The message was stopped before delivery rather than filed after it, which is why it sits outside both your inbox and your junk folder.
- The word folder misleads. In Microsoft 365 and Google Workspace it’s a page on a separate service, and in Google’s case only administrators can see it at all.
- Venice held ships for forty days on suspicion, without destroying anything, for a fixed term. All three properties survived into software, and the third is the one that catches people.
- Junk and quarantine are two destinations for the same verdict, chosen by policy. Junk is yours. Quarantine belongs to the filtering service.
- Everything held has an expiry date, and it ends in permanent deletion. Fifteen days is the common Microsoft default for spam and thirty is Google’s, and the message is beyond recovery after that.
- What you’re allowed to do depends on why it was held. Spam, bulk and impersonation are normally yours to release. Malware, high confidence phishing and rule-based holds belong to an administrator.
- The notification that tells you any of this is heavily impersonated, so the page is worth reaching by an address you keep rather than by a button somebody sent you.
- AI mail clients use the same word for something else: holding unvouched mail away from the assistant so a stranger cannot instruct it. That’s protection for the software rather than a judgment about the message.