How to Search Emails Between Internal Users and an External Domain in Microsoft 365
Question details
The user needs to find a correct KQL query or condition in Microsoft 365 eDiscovery to search for all emails exchanged between internal users and a specific external domain.

- Product
- Microsoft 365 eDiscovery
- Device & OS
- not provided
- Scenario
- Searching for email communications between internal staff and an entire external domain for compliance or auditing purposes.
- Observed behavior
- eDiscovery successfully returns results when querying a full external email address, but fails to accurately retrieve messages when only the external domain name is used.
Ensure you have the necessary eDiscovery Manager permissions assigned in the Microsoft 365 compliance center to execute organization-wide email searches.
Use Keyword Query Language (KQL) for Domain-Level Searches
Construct a specific KQL query using supported message properties and wildcards to accurately target an entire external domain.
Microsoft 365 eDiscovery relies on Keyword Query Language (KQL) to process complex search conditions. When searching for an entire domain rather than a specific email address, using a simple keyword is often insufficient. You must combine wildcards with specific message properties such as 'Participants', 'Sender', or 'To' to correctly filter the emails.
Log in to the Microsoft Purview compliance portal, navigate to eDiscovery, and open your specific case.
Navigate to the Searches tab, click 'New search', and switch to the KQL editor to manually input your query.
Enter a query using the domain wildcard. For example, to find all emails sent to or received from a domain, use: Participants:*@externaldomain.com. Alternatively, you can use: Sender:*@externaldomain.com OR To:*@externaldomain.com.
Execute the search and review the search estimates or sample results to confirm that messages to and from the specified domain are correctly captured.

Open a Service Request for Advanced Support
If your KQL queries are not yielding the expected results, Microsoft support can assist in building the correct search parameters.
Need a Lightweight Alternative for Daily Office Tasks?
While Microsoft 365 manages enterprise email compliance and eDiscovery on the backend, your daily document, spreadsheet, and presentation needs can be handled seamlessly by WPS Office. It provides a free, highly compatible, and user-friendly alternative to traditional desktop office suites.
- 1. Download the installer: Visit the official WPS Office website and click the free download button.
- 2. Install the software: Run the installer file and follow the on-screen instructions to set up WPS Office on your computer.
- 3. Open your files: Launch WPS Office and directly open your existing Microsoft Office files without worrying about formatting issues.

Frequently Asked Questions
Why does my eDiscovery search work for a full email address but not a domain?
Searching by a full email address triggers an exact string match. When searching for an entire domain, standard keyword searches might miss items. You need to use Keyword Query Language (KQL) wildcards (e.g., *@domain.com) combined with specific message properties like Sender or To.
What is Keyword Query Language (KQL) in Microsoft 365?
KQL is the standardized search language used across Microsoft 365 services, including eDiscovery and SharePoint. It allows administrators to build advanced and precise search queries using keywords, properties, and operators like AND, OR, and wildcards.
Where can I find supported message properties for eDiscovery?
Microsoft provides extensive online documentation detailing supported message properties for eDiscovery. Properties most commonly used for email searches include From, To, Cc, Bcc, Participants, and Received.




