Managing security settings and protections in Outlook on the web for business
Adding the address to Safe Senders does not remove the Unverified warning in Outlook.
That warning is based on sender authentication checks, not on the Safe Senders list. Outlook shows it when the sender can’t be fully validated through email authentication methods such as SPF, DKIM, and DMARC. Safe Senders only affects junk filtering, such as helping keep messages out of the Junk Email folder.
What can be confirmed on the recipient side:
- Verify the sender is on the Safe Senders list:
- In Outlook on the web, go to Settings > Mail > Junk email.
- Under Safe senders and domains, add the full email address or the sender’s domain.
- Select Save.
- Check the sender indicators in Outlook:
- If Outlook shows a ? in the sender image, Outlook could not verify the sender identity.
- If Outlook shows a via tag, the actual sending address is different from what appears in the From address.
- In Outlook and new Outlook on the web, hovering over the sender name or address shows the email address without opening the message.
- If the warning still appears, the fix is on the sender side:
- The external sender’s mail system needs correct and aligned SPF, DKIM, and DMARC configuration.
- Until those authentication checks pass consistently, Outlook can continue to show the warning even for a known contact.
Important caution: Using Safe Senders has security tradeoffs. Microsoft notes that this can increase the risk of malicious mail being delivered if a trusted sender is later compromised.
So the practical answer is:
- Safe Senders = controls junk handling
- Unverified warning = controls identity/authentication trust
There is no supported user setting in the provided guidance to manually mark that external sender as fully verified and suppress this warning.