table

EmailPostDeliveryEvents

EmailPostDeliveryEvents contains post-delivery actions taken on email messages after Microsoft 365 delivers them to recipient mailboxes.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeDate and time when the event was recorded.
NetworkMessageIdstringUnique identifier for the email, generated by Microsoft 365.
InternetMessageIdstringPublic-facing identifier set by the sending email system.
ActionstringAction taken on the entity.
ActionTypestringType of activity that triggered the event, such as manual remediation or ZAP.
ActionTriggerstringIndicates whether the action was triggered by an administrator or automated mechanism.
ActionResultstringResult of the action.
RecipientEmailAddressstringEmail address of the recipient.
DeliveryLocationstringLocation where the email was delivered.
ThreatTypesstringVerdict from the email filtering stack.
DetectionMethodsstringMethods used to detect malware, phishing, or other threats.
ReportIdstringEvent identifier based on a repeating counter.
SenderFromAddressstringSender email address in the visible From header.
EmailDirectionstringDirection of the email relative to the organization.
SourceLocationstringLocation where the email triggered zero-hour auto purge.