How to Blacklist Domain or Email Address in Office 365 (Microsoft 365)?

In Microsoft 365 (Office 365) organizations, you can use Exchange Online Protection (EOP) to block email from unwanted senders (SMTP addresses) or domain names. In Exchange Online, you can configure multiple levels of spam blocking:

  • Block domains and email addresses using Tenant Allow/Block List;
  • List of Outlook Blocked Senders (an individual list is stored in each user mailbox);
  • Exchange Online Protection anti-spam policies;
  • Exchange Mail flow (transport) rules;
  • Connection filters (the IP Block List).

The available sender blocking methods in this list are listed in order from most recommended to least recommended.

Manage Exchange Online Tenant Block List

There is a separate Tenant Allow/Block List feature in Microsoft 365 Defender that allows you to manage your list of allowed and blocked external senders.

  1. Sign-in to Microsoft 365 Defender portal with an account that is a member of one of the following groups: Organization Management, Security Administrator role, or role group;
  2. Go to Email and collaboration > Policies and rules > Threat Policies > Tenant Allow/Block Lists; block domain office 365
  3. Click Block to add a new sender to M365 blacklist;
  4. Specify the list of sender domain names and SMTP addresses that you want to block (up to 20 entries at a time);
  5. In the Remove block entry after field, specify the expiration date after which they will be automatically removed from the blacklist. By default, the entries in this list will expire in 30 days, but you can choose one of the following values: 1 day, 7 days, 30 days, up to 90 days from today, or Never expire;
  6. Click the Add button to add entries to the list. block email address office 365

Emails from these senders will be marked as high confidence spam (SCL = 9). In addition, users in your organization won’t be able to send email messages to blocked addresses and domains. When sent to these addresses, users will receive an NDR with the text:

ADVERTISEMENT

‘550 5.7.703 Your message can’t be delivered because one or more recipients are blocked by your organization’s tenant recipient block policy’

You can manage the Exchange Online tenant Allow/Block list with PowerShell. Connect to your Exchange Online organization with the ExO PowerShell module:

Connect-ExchangeOnline -UserPrincipalName admin@theitbros.com

To blacklist a new sender address, run the command:

New-TenantAllowBlockListItems -ListType Sender -Block -Entries 'spam@example1.com','spam@test1.com' -ExpirationDate 12/31/2022

office 365 block email address

To change an entry in the list, use the Set-TenantAllowBlockListItems command:

Set-TenantAllowBlockListItems -ListType Sender -Entries 'spam@example1.com' -NoExpiration

List blocked addresses in Microsoft 365:

Get-TenantAllowBlockListItems -ListType Sender -Block|select value,

ExpirationDate

office 365 block domain

Managing Blocked Senders List in Outlook

Users can block specific email domains or senders in Outlook manually:

  1. If you are using Outlook Web, sign in to your Microsoft 365 mailbox;
  2. Open its Settings;
  3. Got to Mail > Junk email;
  4. Add email addresses and/or external domains from which you do not want to receive emails to the Blocked senders and domains list;
  5. Save changes;
  6. All emails from the specified senders will be automatically moved to the Junk Email Folder. block domain in office 365

You can also display or change the list of blocked emails and domains in the user’s mailbox using PowerShell. Connect to your Exchange Online tenant:

Connect-ExchangeOnline -UserPrincipalName admin@theitbros.com

To display a blacklist in a specific user’s mailbox, run the command:

Get-MailboxJunkEmailConfiguration -Identity jsmith | Format-List BlockedSendersAndDomains

office 365 block sender

Use the following command to add a new sender address to a user’s blacklist:

ADVERTISEMENT
Set-MailboxJunkEmailConfiguration jsmith -BlockedSendersAndDomains @{Add="info@spam.org"}

You can add a specific email to the blocked sender list to all mailboxes in your organization at once:

$All = Get-Mailbox -RecipientTypeDetails UserMailbox -ResultSize Unlimited $All | foreach {Set-MailboxJunkEmailConfiguration $_.Name -BlockedSendersAndDomains @{Add="info@spam.org"} }

Configure Spam Filter Policies in Microsoft 365

To block specific email addresses or domains globally at the organization level, you can create a custom anti-spam policy in the Microsoft 365 Defender:

  1. Sign in to Microsoft 365 Defender portal at https://security.microsoft.com;
  2. Go to Email & Collaboration > Policies & Rules > Threat policies > Anti-spam;
  3. Create a new Inbound policy;
    how to block domain in office 365
  4. Set a unique policy name and description (optional);
  5. Select the users, groups, and domains to which this anti-spam policy should apply. You can specify a list of accepted domains for your organization;
  6. Next, you need to configure the Bulk email threshold & spam properties. Here you can configure the quarantine settings for the inbound email flow. Or you can skip this step if you only want to configure a blacklist;
  7. On the Actions tab, you need to select the action that you want to apply to the inbound email in this rule. You can move the message to the Junk Email folder, delete the email, or send it to quarantine;
  8. Next, you can add individual sender’s SMTP addresses to the blocked Senders list or FQDN domain name to Domains list. Emails from these senders will always be marked as Spam; blacklist email address office 365
  9. Click Next > Create;
  10. Your new anti-spam rule will now apply to all senders on your blacklist.

Please note that you can add a maximum of 1000 entries to this blocked list.

Block Senders with Exchange Online Mail Flow Rules

Another way to block senders in Microsoft 365 is to use mail flow rules.

  1. Sign in Classic Exchange admin center or new Exchange admin center;
  2. Go to Mail flow > Rules > and click Add a rule;
  3. Select Restrict messages by sender or recipient; blacklist domain office 365
  4. Create the following rule conditions:
    Apply this rule if > The sender > domain is > specify the domain name here
    Do the following > Block the message > Delete the message without notifying anyone
    how to block a domain in office 365
  5. In the next step, you can set the rule settings. Select Rule mode > Enforce. Save your mail flow rule.
    block email domain office 365

Now all inbound e-mail messages from this sender will be rejected.

I enjoy technology and developing websites. Since 2012 I'm running a few of my own websites, and share useful content on gadgets, PC administration and website promotion.

One comment

  1. strange, it’s not deleting the address I entered in the list, still just sending it to Junk. It is configured to delete a specified address but our end user is still receiving it in his Junk folder.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.