Microsoft 365

Download 240
Last updated Sep 18, 2026

m365-exchange-mail-flows

Fetch Exchange mail flow message trace logs using the Microsoft Graph message trace API.

Note
App version 1.5.2609.0 and later use the Microsoft Graph message trace API. Earlier versions use the Office 365 Reporting Web Service and return a different set of output fields.
m365-exchange-mail-flows [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
profile=PROFILE
Microsoft 365 connect profile name
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

The query range is limited. Graph message trace keeps only the last 90 days of data, so specifying a start time older than 90 days returns an error. A longer range is split into 10 day chunks internally.

Output Fields

FieldTypeNameDescription
_timeDateTime
profileStringConnect profileMicrosoft 365 connect profile code
mail_fromStringSender addressEmail address format
mail_toStringRecipient addressEmail address format
mail_subjectStringMail subject
sizeLongSizeIn bytes
statusStringStatuse.g. Delivered, Failed, Expanded, Quarantined, FilteredAsSpam
src_ipIP addressSource IPSender mail server IP
dst_ipIP addressDestination IPDestination domain MX IP. Blank for incoming messages
indexIntegerIndexNot provided by Graph API. Reporting API compatibility field
msg_idStringMassage ID
msg_trace_idStringMassage Trace IDGUID format
organizationStringOrganization nameNot provided by Graph API. Reporting API compatibility field
start_dateStringStart dateNot provided by Graph API. Reporting API compatibility field
end_dateStringEnd dateNot provided by Graph API. Reporting API compatibility field