Getting Started
Enki Basic is the free, cloud-only edition of Enki — essential spam and phishing reporting for Microsoft 365, with no user limits. Here's how to deploy the add-in in a few simple steps.
Step 1: Generate Your Manifest URL
Enki Basic is installed from a manifest URL that's unique to your organization. Build it from this template:
https://manifest.addin.eventusenki.com/manifest/spamreport/?submitTo=<your-security-mailbox>
Replace <your-security-mailbox> with the address that should receive reported email — for example, [email protected].
Anyone who has this URL can generate a working manifest that points reports at whatever address they choose. Share it only through internal, trusted channels (your admin center, a password-protected doc), the same way you'd handle any other credential — never post it publicly.
Step 2: Deploy to Outlook
With the manifest URL ready, deploy it the same way you would any other Microsoft 365 add-in. This process varies slightly by Outlook version and by how your organization manages add-ins, so for a full walkthrough — especially for admins deploying to a whole tenant — we recommend Microsoft's own guide:
Manage and deploy add-ins in the Microsoft 365 admin center
Enki Basic works from the Outlook Web App (OWA) and the new Outlook alike, so your team gets the same reporting button no matter how they access mail.
Step 3: Start Reporting with One Click
Once deployed, a Report Phishing button appears in Outlook whenever someone reads a message. Reporting sends the original email straight to the address you configured in Step 1 — no manual forwarding required.
Need send-time warnings for external recipients, on-premise deployment, or Outlook Classic support? Take a look at Enki Standard or Enki Enterprise.