When using Microsoft Purview Message Encryption and IncaMail simultaneously, compatibility issues may arise that cause messages to be delivered incorrectly or the IncaMail add-in to malfunction. This article describes the affected scenarios and provides specific recommendations.
What is Microsoft Purview Message Encryption?
Microsoft Purview Message Encryption is Microsoft’s integrated email encryption solution for Microsoft 365.
It offers the following options, among others:
| Option | Description |
|---|---|
| Encrypt | The message is encrypted and the recipient must authenticate. The recipient can read, copy, print, and forward the message, but cannot export it or remove the encryption. |
| Do Not Forward | The message is encrypted and the recipient must authenticate. Forwarding, printing, and copying the message are not allowed. Additionally, recipients cannot be changed in the address field. |
Known Compatibility Issues
Issue 1 – Purview “Encrypt” Combined with IncaMail
What happens: If a message is sent simultaneously using the Purview “Encrypt” option and via IncaMail, the message appears to be delivered successfully—the sender receives no indication of a problem.
However, the recipient receives a Purview link to open the message instead of the expected message content. To read the message, the recipient must request a one-time passcode that is sent to their email address.
The actual problem: Since the message was sent via IncaMail, the recipient’s address is appended with the suffix .incamail.ch. Microsoft then attempts to send the one-time passcode to this modified address—for example:
max.mustermann@example.com.incamail.ch
This address does not exist as a regular mailbox. The one-time passcode never reaches the recipient and the encrypted message cannot be opened.
⚠️ Recommendation: Use either Microsoft Purview or IncaMail for encrypting a message—never both simultaneously. Both solutions serve the purpose of secure message delivery; combining them results in undeliverable messages.
Issue 2 – IncaMail Add-in When Replying to “Do Not Forward” Messages
What happens: When a message is sent with the Purview “Do Not Forward” option and the recipient tries to reply using the IncaMail add-in, the add-in does not function properly. Permission errors appear in the add-in’s debug log.
The reason: The IncaMail add-in needs to modify the recipient field and subject line when composing a reply. “Do Not Forward” messages prevent exactly these changes—the add-in is blocked by these restrictions.
How to recognize a “Do Not Forward” message: Affected messages are marked in Outlook with a banner above the message:
Do Not Forward – Recipients can't forward, print or copy content⚠️ Recommendation: Before composing a reply, check if the message is marked “Do Not Forward.” In this case, do not use the IncaMail add-in for the reply. Instead, compose a new IncaMail message or reply without IncaMail encryption.
Summary
| Scenario | Problem | Recommendation |
|---|---|---|
| Purview “Encrypt” + IncaMail simultaneously when sending | One-time passcode sent to invalid .incamail.ch address; message cannot be opened | Use only one encryption solution |
| IncaMail add-in when replying to “Do Not Forward” message | Add-in cannot modify recipient and subject fields; permission errors | Do not reply to “Do Not Forward” messages using the IncaMail add-in |