No INKY Analysis or Banners After Moving Out of Journal Mode

Overview

This article helps troubleshoot Microsoft 365 environments where INKY was moved out of Journal mode, users were added to the Include list, but INKY is not analyzing inbound messages and banners are not appearing.

Use this article if you see behavior such as:

  • Email is flowing to users, but INKY banners are not appearing.
  • Users were added to the Include list, but messages are not being analyzed.
  • Analysis or Observations shows no inbound messages.
  • The customer was previously in Journal mode and recently moved to active protection.
  • Mail delivery works, but INKY does not appear to be processing messages.
  • All users are affected after changing deployment phase or include/exclude settings.

Important platform note

Journal mode and phased include/exclude behavior apply to Microsoft 365 deployments.

Google Workspace deployments do not use Journal mode in the same way. For Google Workspace, the IPW group functions as the include group. Users added to the IPW group are included in protection, and users not added to the group are treated as excluded.

If the customer uses Google Workspace, review the Google Workspace routing, IPW group membership, and Email Log Search instead of Journal mode settings.

What this usually means

If mail is still reaching users but INKY shows no analysis and no banners, the issue is usually one of the following:

  • Mail is no longer routing through INKY.
  • The users are not actually included in active protection.
  • Users are still excluded or not matched by the Include list.
  • The wrong tenant, organization, or team is being reviewed in INKY.
  • The change from Journal mode to active mode was not completed.
  • Microsoft 365 connectors or transport rules are not routing mail as expected.
  • The messages being tested are not the type of mail expected to receive INKY analysis or banners.
  • There is a delay between configuration changes and processing visibility.

Step 1: Confirm the customer was moved out of Journal mode

Start by confirming the current deployment state.

Check:

  • Is the customer still in Journal mode?
  • Has it been 24 hours since this change? (Inky can take some time to propagate)
  • Was the customer moved to active protection?
  • Was the phase change completed successfully?
  • Were users moved from Journal mode into the Include list?
  • Were any users left in Exclude or Journal groups?
  • Was the change made for the correct customer tenant/team?
  • Was the change saved successfully?

Step 2: Confirm users are in the Include list

If users are not included in active protection, mail may continue to flow without INKY analysis or banners.

Check:

  • The affected users are in the Include list.
  • The affected users are not in the Exclude list.
  • The affected users are not still assigned to Journal mode only.
  • Group membership has synchronized.
  • The correct group or user list is being used.
  • The affected users belong to the correct tenant/team.
  • Shared mailboxes, aliases, or distribution list recipients are handled as expected.

If all users are affected, review the include/exclude configuration at the tenant or team level.

If only some users are affected, compare an affected user with a working user.

Step 3: Confirm mail is routing through INKY

If email is flowing to users but INKY shows no inbound analysis, mail may be bypassing INKY.

Review Microsoft 365 mail flow.

Check:

  • INKY connectors are present and enabled.
  • Transport rules are present and enabled.
  • Rules are scoped to the correct users, groups, or domains.
  • Rule priority/order is correct.
  • No bypass rule is taking precedence.
  • No old connector or routing rule is interfering.
  • Mail is not routing directly to Microsoft 365 without passing through INKY.
  • Mail is not routing through a previous gateway or security platform instead of INKY.

Run a Microsoft 365 Message Trace for a test message and confirm whether the message followed the expected INKY route.

Step 4: Send a new external test message

After confirming users are included and routing is configured, send a new test message.

Use a message that should be processed by INKY.

Recommended test:

  • Send from an external sender.
  • Send to a user confirmed in the Include list.
  • Use a recent timestamp.
  • Avoid using an internal-only message for the first test.
  • Avoid testing only with messages received before the configuration change.

Then verify:

  • The message is delivered.
  • The message appears in Microsoft 365 Message Trace.
  • The message routes through the expected INKY path.
  • The message appears in INKY Analysis or Observations.
  • The message receives an INKY banner where expected.

 

Step 5: Check Analysis or Observations using the correct organization

If Analysis or Observations shows no inbound messages, confirm that you are viewing the correct customer organization or team.

Check:

  • You are in the correct partner/customer context.
  • You are filtering by the correct organization.
  • You are using the correct org ID, if required.
  • The time range includes the test message.
  • The message was sent after the configuration change.
  • You are checking inbound mail, not only other traffic types.

The organization ID can be found from the Admin Center Summary area. Use that org ID when filtering in Analysis or Observations if needed.

Step 6: Confirm expected banner behavior

Not every email may display the same banner behavior.

Check:

  • Was the message external, internal, or outbound?
  • Was the recipient included in protection?
  • Did the message actually route through INKY?
  • Was the message received after the user was added to the Include list?
  • Is the message type expected to receive an INKY banner?
  • Did any rule bypass INKY processing for this message?

If no users are receiving banners and no inbound messages appear in Analysis, focus first on routing and include/exclude configuration.

If messages appear in Analysis but banners are missing, review banner configuration and message type.

Step 7: Check for configuration timing or sync delay

After moving users out of Journal mode or changing include/exclude settings, allow time for changes to apply.

If the change was just made:

  • Wait for synchronization or processing to complete.
  • Send a new external test message after the change.
  • Avoid using older messages to validate current behavior.
  • Confirm the change was saved successfully.
  • Recheck Analysis or Observations using the correct time range.

If new messages still do not appear after the expected processing window, continue reviewing routing and user inclusion.

Step 8: Review recent onboarding or migration changes

This issue can occur during onboarding, migration, or phase transitions.

Review whether the customer recently:

  • Moved from Journal mode to active protection
  • Added users to the Include list
  • Removed users from Journal mode
  • Changed include/exclude groups
  • Changed Microsoft 365 connectors
  • Changed transport rules
  • Migrated from Graphus or another email security tool
  • Changed MX, routing, or gateway configuration
  • Added bypass rules for testing

If a previous security product or old routing path is still active, mail may bypass INKY or route differently than expected.

Common causes

SymptomPossible causeWhat to check
Mail is delivered but no INKY banners appearMail is bypassing INKYMicrosoft 365 connectors, transport rules, routing
No inbound messages in Analysis or ObservationsINKY is not processing the messages or wrong org is selectedRouting, org filter, org ID, time range
Users were added to Include list but still not analyzedUsers are not matched or sync has not completedInclude/exclude groups, user assignment, timing
All users affectedTenant-level routing or deployment state issueJournal/active mode, connectors, transport rules
Only some users affectedUser/group assignment issueCompare included vs affected users
Test message does not show in INKYMessage did not route through INKY or wrong time/org filterMessage Trace and Observations
Google Workspace customer reports this issueJournal mode does not apply the same wayIPW group, Google routing, Email Log Search

Information to gather before contacting support

If messages are still not being analyzed after reviewing the steps above, gather one affected test example.

Include:

  • Customer or team name
  • Microsoft 365 tenant ID, if available
  • Customer domain
  • Affected user email address
  • Whether all users or only some users are affected
  • Date and time the customer was moved out of Journal mode
  • Date and time users were added to the Include list
  • Screenshot of Include/Exclude/Journal configuration
  • Screenshot of Microsoft 365 connector and transport rule configuration
  • Sender address
  • Recipient address
  • Subject line
  • Date and time of the test message, including time zone
  • Microsoft 365 Message Trace result for the test message
  • Screenshot of INKY Analysis or Observations showing no inbound messages
  • Org ID used for filtering, if applicable
  • Whether any previous Graphus, INKY, or third-party mail routing configuration exists
  • Verify if 24 hours have passed after switching from Journal Mode as it can take some time for INKY services to Propagate correctly at times. 

 

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section