Help › Mail
Open an encrypted message
Banks, insurers and law firms often send documents using Microsoft Purview
Message Encryption. What arrives in your mailbox is not the document: it is
a wrapper, and the real content is a locked attachment (message_v2.rpmsg)
that only Microsoft can unlock.
TALISK_HQ shows a Encrypted message panel in place of that wrapper, with a button to open the message. Outlook can read these in place because it is a Microsoft rights-management client; TALISK_HQ, Gmail, Apple Mail and every other mail app show the same kind of hand-off.
Open it
The panel offers one or two buttons, depending on what the sender's system put in the message.
- Open the secure portal opens Microsoft's own page for the message. It signs you in itself, or emails you a one-time passcode, so it works in any browser.
- Open in Outlook opens the message in Outlook on the web, in your own mailbox. This one needs you to be signed in to Microsoft in your browser already.
If the panel offers both, use the secure portal: it is the one that does not depend on an existing session.
"This page isn't working — HTTP ERROR 401"
That is the Open in Outlook link, and it means the browser it opened in has no Microsoft session. It is not a sign the link has expired or been used up: reading or replying to the message in Outlook does not consume it.
Two things to try:
- Open https://outlook.office.com/mail/ in the same browser, sign in as the mailbox the message was sent to, then click the button again.
- If the message also offers Open the secure portal, use that instead.
Two messages in the same conversation can offer different buttons, so one may open and another may not. That is a difference in what the sender's system attached to each message, not something that changed at your end.
If you use the TALISK_HQ desktop app, the button opens your default browser. If your Microsoft session lives in a different browser, sign in there or copy the link across.
Why TALISK_HQ cannot just show it
The content is encrypted to your identity and can only be unlocked by a Microsoft rights-management client. Microsoft's own mail API deliberately hands other apps the wrapper and nothing else, so there is no way for TALISK_HQ to read it for you.
Scanning for a bill
Scan for a bill is switched off on an encrypted message. The only text TALISK_HQ can read is Microsoft's wrapper, so a scan would spend an extraction and find nothing, then report "no bill found" about a message that may well be an invoice. If the encrypted message turns out to contain a bill, open it with one of the buttons above, save the document, and add it from Ledger, Expenses instead.