logo
search
Compliance Problems

Fix Purview Content Search Returning Identical Received and Sent Email Counts

Huda QurayshiHuda Qurayshi Sep 25, 2026 869 views

Question details

User is experiencing identical return counts for sent and received messages when performing a Purview Content Search.

How to Fix Purview Content Search Returning Identical Received and Sent Email Counts
Product
Microsoft Purview
Device & OS
not provided
Scenario
Running a content search in Microsoft Purview for Exchange Online emails.
Observed behavior
The search returns the exact same number of results for both received and sent email queries, indicating a potential issue with query syntax, filters, or deduplication settings.
Before you start

Ensure you have the necessary eDiscovery or Compliance Administrator permissions in Microsoft Purview to create, edit, and review content searches.

Solution 1Recommended

Verify KQL Syntax and Deduplication Settings in Purview

Check your Keyword Query Language (KQL) syntax and ensure deduplication settings are not artificially merging results to make sent and received counts identical.

Identical search result counts for sent and received emails are often caused by overly broad KQL queries or enabled deduplication features. When deduplication is active, Purview merges duplicate copies of emails (e.g., an email in the sender's Sent Items and the recipient's Inbox), which can equalize the count.

1
Access Microsoft Purview

Log in to the Microsoft Purview compliance portal and navigate to the Content Search section.

2
Review KQL Query Syntax

Open your search and review the query. Ensure the conditions for the 'received' and 'sent' date fields are correctly distinguished and not overlapping.

3
Check Deduplication Settings

Look at your search export or display settings to see if deduplication is enabled. If it is, temporarily disable it to see if the raw counts for sent and received emails differ.

4
Refine Date Filters and Subject Conditions

Verify that your date range and subject condition filters are applied specifically to the inbound or outbound query as intended.

5
Run Search and Compare

Re-run the content search with the updated filters and disabled deduplication to confirm whether the result counts now accurately reflect the separate received and sent metrics.

Verify KQL Syntax and Deduplication Settings in Purview
Specialized Assistance: If the issue continues, consider posting your specific query and search configuration in the Microsoft Purview section of Microsoft Q&A for specialized troubleshooting.
Free Microsoft Office alternative

Looking for a Lightweight Microsoft Office Alternative?

While Microsoft Purview handles complex enterprise compliance for Exchange, everyday document, spreadsheet, and presentation tasks can be easily managed with WPS Office. It is a free, highly compatible alternative to Microsoft Office that is perfect for users wanting a faster, simpler experience without a heavy subscription.

  1. 1. Download WPS Office: Visit the official WPS Office website to download the free installation package for your operating system.
  2. 2. Install and Set as Default: Run the installer and follow the prompts. During setup, you can choose to set WPS Office as the default app for standard Office formats.
  3. 3. Open Your Documents: Double-click any existing .docx, .xlsx, or .pptx file to open it instantly in WPS Office without losing formatting.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight application that runs smoothly on Windows, Mac, Linux, iOS, and Android.Built-in PDF editing tools for seamless document management.Familiar user interface allowing for a quick and seamless transition from Microsoft Office.
microsoft office alternative - wps office

Frequently Asked Questions

Why does deduplication cause identical email counts in Purview?

When deduplication is enabled, Purview removes duplicate copies of the same message found across different mailboxes. If a message was sent and received within the searched scope, the deduplication process consolidates them into one item, which can result in identical counts for the overall sent and received search results.

What is KQL in Microsoft Purview Content Search?

Keyword Query Language (KQL) is the advanced query syntax used in Microsoft Purview to search for specific terms, metadata, and conditions across Exchange Online, SharePoint, and other Microsoft 365 services.

How do I correctly format date ranges in a Purview KQL search?

You should use the standard KQL date format (e.g., received:01/01/2023..12/31/2023). Make sure you specify either the 'sent:' or 'received:' property clearly depending on whether you are querying outbound or inbound communications to avoid mixing the results.