User Guide

CALENDARguardian™ website, Outlook add-in and mobile apps · DealDoctor PLLC · Updated September 20, 2026

Important: CalendarGuardian reduces calendar-spam risk but cannot guarantee that every malicious invitation will be detected or that every flagged invitation is malicious. Review important events and use automatic removal cautiously.

Start here: scan, review, and confirm the outcome

  1. Open CalendarGuardian or the mobile app and sign in. In Calendars, connect the Microsoft or Google calendar accounts you want protected. On mobile, grant calendar access and select the calendars stored on that device.
  2. If you also want invitation emails checked, open Email, choose the mailbox provider and folders, and authorize email scanning separately. Connecting a calendar does not connect its email.
  3. Open Scan and select Scan everything now. While scanning, the activity indicator, finished-source count, and live message or event counts show what is happening. A source can take longer than another; no percentage is shown when the total work is unknown.
  4. Check each source's outcome. Completed applies only to that source and its stated date range. Failed or Incomplete means the check did not finish. Zero flagged during a failed scan does not mean the mailbox is clean.
  5. Use the review links near the scan button to jump to calendar or email findings. You can review the last completed email scan while a newer attempt runs or fails; its date is displayed.
  6. Select individual invitations, or Select all needing review, then use the bulk action. Read the confirmation: a block saves a continuing sender rule. Calendar actions remove selected events; authorized email cleanup queues matching invitation emails for Trash/Deleted Items. Each connection needs its own cleanup permission.
  7. Read the individual action results near the scan controls. Each selected item has its own success or failure. A partial bulk failure does not undo successful items. Failed items remain available to review.

Handled calendar rows remain visible during this visit with their updated status. Recent action messages stay on the current page until you reload it. For saved calendar outcomes, use Calendar review → Show → Removed or Approved. Saved sender rules appear in Rules. Email findings belong to the latest completed email scan. Invitation email activity is separate and retains the removal outcomes after those findings change.

Calendar actions and email actions are different

ControlWhat succeedsWhat remains
Calendar: Block Sender & RemoveSaves an exact organizer block in CalendarGuardian and removes the selected calendar event.Matching invitation emails are queued for cleanup only in mailboxes with invitation cleanup enabled. Without that permission, the email remains. Provider mail delivery is unchanged.
Calendar: Remove OnlyRemoves the selected calendar event.Sender rules and invitation emails are unchanged.
Email: Block / Block selectedSaves continuing block rules and queues invitation cleanup in authorized mailboxes.Matching invitation emails move to Trash/Deleted Items. Ordinary emails are excluded. Provider delivery is not blocked. Check activity for confirmed removals.
Approve invitationKeeps the item and records this review decision.It does not create a sender trust rule or send an RSVP.

One successful block is enough for the same exact address. The address to be blocked appears on the finding. If the invitation has no usable organizer address, CalendarGuardian uses the email’s From address. It never guesses an address from a name, recipient, or link. Another address is a different sender, even if the invitation has the same title. An email row covered by a saved rule shows its saved decision instead of asking for another block. Earlier scan results missing sender details refresh automatically. If neither the invitation nor its email supplies a usable address, Block is unavailable and the finding explains why; Approve remains available. To change a sender rule, use Rules.

CalendarGuardian's email feature looks for meeting requests and calendar attachments. It is not a general junk-email cleaner. Ordinary advertising messages may not be invitation candidates. If email cleanup is off or has not completed, removing an event can leave Outlook showing “We couldn't find this meeting in the calendar” while the original email remains.

Outlook compatibility, mailbox access and subscriptions

Installing CALENDARguardian™ in Outlook does not protect every mailbox in that Outlook installation. Add-in availability depends on the Outlook client and the mailbox that owns the selected item. Each calendar or mailbox also needs its own CALENDARguardian™ connection and authorization.

Which mailboxes support the Outlook add-in?

Use an Outlook.com personal mailbox or Microsoft 365 business mailbox in a supported Outlook client. Organizational administrators may restrict add-ins or provider consent. For a supported mailbox, check Outlook's Apps menu and whether CALENDARguardian™ is installed for that account.

Microsoft does not support Outlook web add-ins on Yahoo, Gmail or other non-Microsoft mailboxes in classic or new Outlook for Windows, Outlook on the web, or Outlook mobile. Adding Yahoo or Gmail to Outlook does not change its mailbox provider or enable the add-in for that mailbox.

Outlook for Mac has a limited exception for non-Microsoft accounts added with IMAP CloudCache, not IMAP Direct. CALENDARguardian™ has not been validated for that exception, so it is not part of our claimed compatibility. The current CALENDARguardian™ Outlook package targets desktop/web Outlook and does not enable commands inside Outlook for iOS or Android. The separate CALENDARguardian™ mobile apps are distinct from the Outlook add-in.

How do I protect Yahoo or another external mailbox?

Where your provider is available, open Email in CALENDARguardian™, select the provider that holds the mailbox, choose folders and complete its authorization. Enable invitation cleanup separately if you want matching invitation emails moved to Trash or Deleted Items. This is a server-side mailbox connection, independent of adding the account to Outlook; it does not enable ribbon commands on an unsupported mailbox. A calendar connection alone does not authorize email scanning. Provider availability and account restrictions still apply.

Do I need a paid Microsoft 365 subscription?

Not universally. Outlook.com personal mailboxes support add-ins. You still need any license required for your chosen Outlook application or business mailbox. CALENDARguardian™ has its own subscription after the applicable trial; it does not include or replace Microsoft licensing.

See Microsoft's supported Outlook clients and mailbox accounts for platform requirements.

If a Yahoo scan fails

Read the error under Yahoo email in Scan. Calendar-source success does not establish Yahoo success. Any last completed findings remain available, clearly dated, but do not describe messages that the failed attempt never checked.

Enable invitation email cleanup

Enable cleanup once per mailbox, not per invitation. It applies to all existing and future invitation emails matching your shared block rules. Each mailbox needs its own write permission. A block is saved once; later scans apply it automatically where cleanup is enabled.

  1. Open Email, connect your mailbox, and select Inbox and/or Junk/Spam.
  2. Read and select the invitation-cleanup permission, then choose Enable invitation cleanup. You can also enable it from that mailbox's Scan report. Microsoft and Google require renewed provider authorization; choose the same mailbox. Yahoo and iCloud use the existing connection.
  3. On Scan, select invitations individually or use Select all needing review, then Block selected. One block saves a continuing sender rule. Existing saved rules also apply once cleanup is enabled.
  4. Read Invitation email activity for confirmed moves, failures, or messages that were left in place. A queued action is not a completed removal. Results remain visible after later scans replace the review list. Use Scan again to retry failures.

Choose an Email scan window of 7, 30 or 90 days in Email or beneath the mailbox in Scan. The default is 30 UTC calendar days, including today. Changing it stops the current scan and checks the selected window. Initial scans and requested cleanup use that bounded window. On Scan, manual scans default to the last 30 and next 30 days. Historical 7-, 30-, and 90-day periods and custom From/Through dates (up to 90 days) remain available. Both selected dates are included, in UTC. Email uses received dates and calendars use event dates. Custom scans do not change the automatic email checkpoint. Automatic checks use the previous successful scan with a one-day overlap, within the selected window. There are no all-history scans. The report shows the actual start and end dates. Message counts include metadata checked to identify invitations, not only invitations found. Unresolved findings from earlier scans stay visible for review. Each scan has a ten-minute deadline; an incomplete scan does not advance the successful checkpoint. Bulk/Spam is checked first when cleanup is enabled. Yahoo and iCloud cleanup can move identified blocked invitations while the rest of the scan continues. It moves only messages whose contained invitations all match block rules and have not been explicitly approved. Future checks run daily (every 24 hours). Ordinary emails are excluded, even from blocked addresses. Calendar catch-up checks use the last 30 days and next 180 days; native/device and provider restrictions still apply. Calendar and email counts are separate. This does not prevent delivery or change Yahoo, Microsoft, Google or Apple blocked-sender lists.

Turn off invitation cleanup in Email to keep read-only scanning. Turn off scanning to remove stored email credentials, results and action history. To restore email, use your provider's Trash/Deleted Items before its retention expires. Remove a rule in Rules to unblock future invitations; this does not restore past removals. The service retains up to 1,000 email action records and displays the latest 100.

Automatic cleanup on a phone or tablet

In Calendars, enable automatic removal of device invitations matching your saved blocks. This permission starts off. It applies to selected, editable device calendars when the app scans. Approved invitations and events you organize are kept. Phone background scheduling is controlled by the operating system; it does not guarantee immediate removal or prevent new invitations arriving. Connected server calendars and email cleanup have separate controls.

After an action, check its receipt and history. Removed means removal was confirmed. Queued or Removing means it is still pending. Not found does not prove CalendarGuardian removed it. Failed means the item needs attention; the explanation remains visible. A saved block does not mean every matching item has already been removed. Manual calendar scans use the date range selected on Scan. To undo an event removal, use Restore Copy; it creates a copy and does not rejoin the original meeting or unblock the sender.

1. Start your trial

The service-account 14-day trial starts when account creation is completed and does not require a credit card. Apple App Store and Google Play may provide a 14-day introductory trial when the store marks the purchasing account eligible. At the end of the applicable trial, protected features pause unless you subscribe for the annual price shown by the purchase channel; the base U.S. price is $19.99 per year.

Website billing uses Stripe. The Apple app uses StoreKit 2 and the Android app uses Google Play Billing; each native app verifies the current store entitlement and offers a restore-purchase control. A purchase covers one individual user and the product/platform entitlement shown by that purchase channel unless CalendarGuardian expressly confirms account linking.

2. Before you connect

Choose Sign in or Create account. Email-and-password accounts verify email ownership before you choose a password. Existing users can continue with their Microsoft or Google account. Sign-in does not grant calendar or mailbox permission. A connection is shown as verified only after the selected provider accepts its authorization. When account email delivery is enabled, a connection security email records the address and verification details. Use Calendars to connect and configure calendars, Email to authorize mailboxes, Scan to check all connected sources, Rules to manage allowed and blocked lists, and Account for your profile, devices, subscription, and sign-out. The Scan report shows progress and counts by source; incomplete or failed sources remain clearly marked.

Before a connection can begin, you must affirmatively check the connection-consent box. By checking it and selecting Connect, you:

CalendarGuardian records the acceptance time, method, and versions of the legal documents. The server will not start the OAuth connection unless current consent has been recorded.

3. What happens when you connect

  1. You accept the CalendarGuardian legal and authorization disclosure.
  2. CalendarGuardian sends you to the provider's official authorization page.
  3. You sign in directly with the provider and approve the listed permissions.
  4. The provider returns a one-time authorization code to CalendarGuardian.
  5. CalendarGuardian exchanges that code for OAuth tokens, encrypts the stored token bundle, creates the service account record, and starts a secure browser session.
  6. CalendarGuardian creates or renews a provider change-notification subscription and queues a catch-up scan.
  7. The dashboard displays whether the protection channel is active, needs attention, or requires setup.

Microsoft permissions

PermissionWhy it is needed
User.ReadIdentifies the connected Microsoft account and creates the CalendarGuardian profile.
Calendars.ReadWriteReads invitations for scoring and performs calendar actions you request, such as removal or restoration.
MailboxSettings.ReadWriteCreates the colored CalendarGuardian Review and CalendarGuardian High Risk category definitions used to mark flagged Outlook events. It does not grant access to email content.

CalendarGuardian does not request general mailbox-reading permission in its base Microsoft connection. Microsoft Graph does not provide a general production API for reporting a calendar event as junk. A CalendarGuardian report is therefore recorded and enforced by CalendarGuardian unless the product expressly states that a provider report was also accepted.

Google permissions

The Google connector requests openid, email, and profile to identify the connected account; calendar.events to inspect and modify events across writable calendars; and calendar.calendarlist.readonly to discover those calendars. Google Calendar does not expose a general public calendar-event spam-reporting API.

Multiple accounts and calendars

One CalendarGuardian profile can link multiple Microsoft and Google accounts. Select Add Microsoft Account or Add Google Account, approve that provider account, and select an account to manage its setup details. The Scan tab includes all linked calendar accounts. Filter settings and personal rules are shared across linked accounts.

One Google account connection covers all writable calendars discovered in that Google account. One Microsoft account connection covers all editable calendars discovered in that Microsoft account. In Outlook, the add-in identifies the mailbox that owns the open invitation and uses the matching linked Microsoft connection; an unconnected mailbox must be connected before CalendarGuardian can act on its events.

Apple, Android, and Yahoo-synchronized calendars

The native Apple app reads calendars already exposed by EventKit, and the native Android app reads calendars already exposed by Android Calendar Provider. Grant the requested Calendar permission, choose eligible calendars, then scan. The apps offer Approve This Invite, Trust Sender & Approve, Block & Remove, Remove Only, and Restore Copy. An Apple app linked with a single-use code uses the same service-side scoring engine, supported rules, approvals, and decision history as the website and Outlook add-in. An unlinked Apple app and the current Android app score locally. Up to 100 native removal-history records also stay in app-private storage for restore-copy support.

To prevent duplicate processing, a linked Apple app identifies Microsoft and Google calendar sources already protected through the same CalendarGuardian profile and lists them as server-managed instead of offering a second on-device scan. Birthday, subscribed, and read-only calendars are shown as ineligible. Apple, iCloud, Yahoo-synchronized, local, and other writable calendars not already server-managed can be selected individually.

Yahoo calendars are supported only when the Yahoo account is already synchronized onto the Apple or Android device. CalendarGuardian labels that source as Yahoo-synchronized and does not collect the Yahoo password. There is no CalendarGuardian add-in inside Yahoo Calendar. Yahoo email is a separate optional connection in Email and uses a Yahoo-generated app password.

4. Information CalendarGuardian processes

CalendarGuardian may process an event identifier, subject, organizer name and address, organizer domain, attendees, time, recurrence, location, response status, body or preview, links, and related metadata. It also stores protection settings, trusted and blocked rules, action records, connection health, and detection history.

Allowed-event content is designed to be processed transiently for scoring. Detection history retains limited information needed to explain the result. Flagged, reported, or removed events may have an encrypted snapshot retained for review or restore-copy purposes, subject to the retention periods in the Privacy Policy.

5. How scanning works

CalendarGuardian automatically evaluates new or changed invitations received through the active provider subscription. Scan everything now scans the date range selected on Scan, defaulting to the last 30 and next 30 days. Items outside the selected dates are not assessed. Use custom dates for a different future period. The same range applies to writable connected calendars and selected device calendars.

The current rules-based engine considers suspicious language, links, organizer anomalies, invitation patterns, hidden or deceptive content, selected metadata, your personal rules, and enabled malicious-link intelligence. It can produce false positives and false negatives.

Threat intelligence: CalendarGuardian downloads enabled malicious-domain intelligence to its server cache and matches invitation-link domains locally. Calendar invitation data is not sent to the feed provider. A feed match raises the event to high risk but does not bypass your automatic-removal setting.

Risk score

ScoreMeaningDefault treatment
0–54No or weak built-in warning signals. This does not prove the event is safe.Allowed and recorded in detection history.
55–89Suspicious enough to require review.Flagged for review.
90–100High risk.Flagged; eligible for score-based automatic removal only when that setting is enabled.
100 after a user reportYou confirmed the invitation as spam.Confirmed-spam status is preserved against later rescans.

Repeated scans of the same provider event are consolidated into one current detection result. Separate provider event objects can still appear separately even when their subjects look identical.

Check the appointment open in Outlook

The add-in reads the subject, organizer, time, location and body of the appointment currently open in Outlook. Its current-appointment result is separate from Scan everything and is not restricted by that scan's date range. Select Check this appointment after editing it or if Outlook has not returned its fields. A failed read is shown as Not assessed, not a clean result.

For an organizer appointment, CalendarGuardian checks the draft content without saving or sending it. For an attendee appointment, block and remove controls remain unavailable until the matching saved calendar copy is confirmed in the connected Microsoft mailbox. Approve controls apply to invitations awaiting CalendarGuardian review. Checking the current appointment alone does not flag or remove it; background protection and explicit actions remain separate.

6. What each action does

Work inside the calendar: suspicious Outlook events receive a CalendarGuardian category and suspicious Google events receive a CalendarGuardian color. Open the event to use CalendarGuardian controls in the Outlook task pane or Google Calendar add-on. Those controls and CalendarGuardian.com call the same service actions, so review decisions, rules, event removals, and history remain synchronized. Keeping an unchanged event clears its CalendarGuardian marker and prevents the same event from being repeatedly re-flagged; a material event change can trigger a new review.

ActionCurrent eventFuture invitations
Approve This InviteKeeps the event and clears its CalendarGuardian review marker.Does not create a trust or block rule.
Trust Sender & ApproveKeeps the event and clears its CalendarGuardian review marker.Adds a bounded CalendarGuardian trust rule for the exact organizer address.
Block Sender & RemoveRecords confirmed spam in CalendarGuardian and removes the selected event.Adds a CalendarGuardian block for the exact organizer address. Future matches score 100 and are removed automatically.
Block Future Invites from SenderKeeps the current event.Blocks the exact organizer address in CalendarGuardian. Future matches score 100 and are removed automatically.
Block domainKeeps the current event unless combined with a removal action.Applies broadly to future invitations from the entire domain. Use cautiously because legitimate senders may share the domain.
Remove OnlyRemoves the selected event.Does not create a block rule.
KeepDismisses the review item.Does not trust or block the sender.
Trust sender/domainDoes not change the event.Reduces future risk scores by a bounded amount. Trust does not override an explicit block.
Review keyword or phraseDoes not change the event by itself.Raises a matching future invitation to at least 60/100 so it is flagged for review. Matching is case-insensitive across the subject, body/preview, and location.
Restore CopyRecreates available details as a new local calendar event.Does not reconstruct the organizer's original meeting relationship or attendee state.

CalendarGuardian block versus provider block: a block is a CalendarGuardian protection rule. It does not block email or create a Microsoft, Google, Apple, Exchange, or network-level block unless the interface expressly says so.

7. Automatic removal

Score-based automatic removal is off by default. If enabled, an event at or above the selected threshold may be removed after CalendarGuardian first stores the review snapshot. An explicit sender or domain block is different: future matching invitations are automatically removed even when score-based automatic removal is off.

CalendarGuardian never automatically accepts, tentatively accepts, or declines an invitation. Provider deletion and attendee-notification behavior can vary by provider and account type, so important calendars should be reviewed regularly.

Calendar filter on/off

The Calendar filter switch is the master control. Turning it off removes the provider change-notification subscription and stops automatic scans, renewal jobs, and automatic actions. The encrypted provider authorization remains so protection can be resumed without a new sign-in. Manual spam reports and actions you explicitly request remain available. Turning the filter on recreates the provider subscription and queues a catch-up scan.

8. Detection history and review

Detection history includes allowed, suspicious, high-risk, and confirmed-spam scans. Open a row to see its status, source, score, and recorded reasons. A low score means only that the current rules found weak or no signals.

Calendar review is the action queue for suspicious, confirmed, removed, dismissed, or restored items. Use it to keep, remove, report/block/remove, or restore a copy where supported.

9. Connection health and troubleshooting

Select Verify Connection to renew the provider subscription and queue a recovery scan. If authorization fails, reconnect and review the provider permission screen. Never send passwords, OAuth codes, access tokens, or client secrets to support.

10. Privacy, security, revocation, and deletion

See the Privacy Policy, Security page, and Data Deletion page for additional details.

11. Support

Email support@dealdoctor.pro. The ordinary support-response target is one business day. Include the visible error message and support-reference identifier, but do not include passwords, OAuth authorization codes, tokens, provider secrets, or unnecessary calendar content.

Password recovery

Choose Forgot password on the Sign in screen. The email link expires after 30 minutes and works once. Your old password remains active until you submit a new one. After a successful reset, sign in again on each device. If you have only used Microsoft or Google, choose Set up email-and-password sign-in in Account and verify that same email address to add a password without restarting your trial.

Automatic invitation blocking and content rules

Optional automatic email blocking creates sender blocks for high-risk invitations scoring at least 90/100 and saves a hash of sufficiently detailed invitation content. Matching content is recognized even when the sender changes. Exact matching normalizes spacing, letter case and common tracking tags. Conservative near-duplicate matching also requires substantial shared invitation text and a shared campaign link host; common calendar-service link hosts cannot establish that match. Short text and subject-only matches do not create content rules. Manual invitation blocks also save eligible content rules, independently of the automatic-blocking setting. Content rules synchronize across your protected connections. Approved invitations and trusted senders are excluded from automatic email blocking and cleanup. Ordinary email is excluded. Lower-confidence findings remain available for review. Turning automatic blocking off stops new automatic rules; saved rules continue until removed in Rules. Cleanup remains separately controlled, and moved email can be restored from Trash before the provider deletes it under its retention policy.