What "Add External Tag to Email" Means in Microsoft Attack Simulator
Question details
Users want to understand the purpose of the "Add External Tag to Email" option in Microsoft Attack Simulator and whether different Outlook configurations can hide the indicator.

- Product
- Microsoft Defender for Office 365
- Device & OS
- not provided
- Scenario
- Configuring simulated phishing attacks to test user awareness and ensuring the emails mimic realistic external threats.
- Observed behavior
- The "External" tag is applied to simulated messages, but its visibility varies among users due to individual Outlook display settings, metadata configurations, or inbox rules.
Ensure you have administrator access to the Microsoft Defender portal and understand your organization's default Exchange Online external tagging policies before launching a simulation.
Understanding and Verifying the External Tag in Outlook
Learn how the external sender indicator is applied to simulated emails and why its visibility might differ across user mailboxes.
The "Add External Tag to Email" option is designed to append an "External" indicator to your simulated phishing messages. This makes the payload closely resemble a legitimate, real-world message originating from outside your organization, providing a more accurate test of user vigilance.
However, the actual display of this tag is influenced by client-side configurations, meaning not every user will experience the email exactly the same way in their inbox list view.
During simulation setup, checking the 'Add External Tag to Email' box modifies the message metadata to trigger Outlook's native external sender warning, helping users identify potential external threats.
Keep in mind that users can customize which metadata columns are displayed in their Outlook email view. If a user has modified their view to hide sender tags or is using a legacy client that doesn't fully support the feature, they may not see the tag in the message list.
Inbox rules configured by the user might automatically redirect the simulated email to folders other than the primary Inbox. While the tag might not be obvious in a secondary folder's list view, the external indicator should remain visible when the user double-clicks to open the message.

Discover WPS Office for Your Daily Document Needs
While enterprise email security and attack simulations require specialized tools like Microsoft Defender, your everyday document, spreadsheet, and presentation tasks do not need an expensive subscription. WPS Office provides a free, lightweight, and robust suite for handling all your office workflows.
- 1. Download WPS Office: Visit the official WPS website to download the free office suite for Windows, Mac, or Linux.
- 2. Install the application: Run the setup file and follow the straightforward on-screen instructions to install WPS Office on your device.
- 3. Open your existing files: Launch WPS Office and seamlessly open your Word, Excel, or PowerPoint documents without worrying about formatting loss.

Frequently Asked Questions
Why do some users fail to see the external tag in their Outlook inbox?
Users might not see the tag in their message list because their specific Outlook view is configured differently. If they have customized their column metadata or are using an older version of the Outlook client, the external sender indicator might be hidden from the primary list view.
Does moving an email with an inbox rule remove the external tag?
No, client-side inbox rules do not strip the external tag metadata from the email. Even if a rule moves the message to a subfolder or a junk folder, the "External" indicator should still be visible once the email is fully opened by the user.
Can I force the external tag to display for all users regardless of their settings?
While administrators can enable external tagging globally at the Exchange Online tenant level, individual client-side Outlook view settings and the specific version of the email client being used can still dictate exactly how and where the tag is displayed.




