logo
search
Email Search Issues

How to Search a Mailbox for Multiple External Email Domains in Microsoft 365

Emma BrownEmma Brown Oct 9, 2026 869 views

Question details

The user needs to find a way to search Microsoft 365 mailboxes for multiple external email domains using supported query syntax.

How to Search a Mailbox for Multiple External Email Domains in Microsoft 365
Product
Microsoft 365
Device & OS
not provided
Scenario
Performing an administrative or compliance search across user mailboxes to track correspondence with specific external companies or domains.
Observed behavior
Standard wildcards like *@gmail.com may not function correctly in every keyword or recipient field, causing search results to be incomplete or inaccurate.
Before you start

Ensure you have the required eDiscovery Manager or Compliance Administrator roles assigned in the Microsoft Purview compliance portal before attempting to run a Content Search.

Solution 1Recommended

Use Microsoft Purview Content Search with KQL Syntax

Build a precise Keyword Query Language (KQL) query in the Purview compliance portal using specific sender and recipient properties.

Because standard wildcards can behave unpredictably in general keyword fields, it is best to restrict your search queries to specific email properties like 'sender' or 'recipients'. Combining these conditions using OR operators ensures accurate retrieval of emails from multiple external domains.

1
Access the Compliance Portal

Log in to the Microsoft Purview compliance portal using your admin credentials and navigate to 'Content search' under the Solutions menu.

2
Create a New Search

Click the 'New search' button. Provide a clear name and description for your search query, then click 'Next'.

3
Select Mailbox Locations

Toggle on 'Exchange mailboxes'. You can choose to search all mailboxes in the organization or click 'Choose users, groups, or teams' to specify specific mailboxes.

4
Build the KQL Query

In the conditions builder, switch to the KQL editor. Input a query using supported properties, for example: sender:"*@domain1.com" OR sender:"*@domain2.com".

5
Submit and Review Results

Submit the search and wait for it to complete. Click on the search name to review the search statistics, sample results, and export the data if required.

Use Microsoft Purview Content Search with KQL Syntax
Wildcard Testing: Always test your queries on a small, known sample size first. Ensure that your KQL syntax accurately captures subdomains if they are relevant to your external domain search.
Free Microsoft Office alternative

Boost Your Daily Productivity with WPS Office

While advanced mailbox searches require Microsoft 365 administrative tools, you don't need expensive subscriptions for your daily document tasks. WPS Office is a highly compatible, feature-rich suite designed to handle all your Word, Excel, and PowerPoint needs effortlessly.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install the Software: Run the downloaded installer file and follow the quick on-screen instructions to set up the software.
  3. 3. Open and Edit Your Files: Launch WPS Office and open your existing Microsoft Office files directly to begin editing with zero format loss.
Seamless compatibility with Microsoft Office formats (.docx, .xlsx, .pptx)Free, lightweight, and fast-loading alternative to traditional Office appsFamiliar tabbed interface makes migrating from Microsoft 365 incredibly easyBuilt-in PDF editing and AI-powered writing tools
microsoft office alternative - wps office

Frequently Asked Questions

Why does the *@domain.com wildcard fail in a general search?

In Microsoft Purview, prefix wildcards are typically only supported in specific email properties (like Sender, From, or To). When typed into a general keyword field, the search engine may not parse the wildcard correctly, leading to incomplete indexing or errors.

Can I search for both the main domain and its subdomains at once?

While some queries might cascade to subdomains, it is highly recommended to explicitly state subdomains using the OR operator in your KQL query (e.g., sender:"*@domain.com" OR sender:"*@sub.domain.com") to guarantee comprehensive results.

Why can't I see the Content Search option in Microsoft 365?

You likely lack the necessary permissions. Even Global Administrators do not have eDiscovery rights by default. You must go to the Purview compliance portal's Permissions section and assign yourself the eDiscovery Manager role.