This guide covers how to create a blocked senders list in Microsoft 365 and Exchange Online, and how to add a specific domain or email address to the block list.
In Microsoft 365 (Exchange Online) organizations there are several different tools available to block email from unwanted senders.
Here are the most common sender blocking mechanisms used in Microsoft 365:
Tenant Allow/Block List Rules in Microsoft Defender portal.
Anti-Spam Policies in Microsoft 365 Defender.
Exchange Online Mail Flow Rules.
Outlook Blocked Senders List.
In addition to sender and domain block lists, Microsoft Defender for Office 365 includes advanced anti-phishing protections (such as Spoof Intelligence and Anti-Phishing Policies).
These features help you to detect and block:
Domain spoofing attacks
Display name impersonation
Lookalike domains
Business Email Compromise (BEC) campaigns
In many phishing investigations, you should use Spoof Intelligence and Anti-Phishing Policies together with Tenant Allow/Block Lists rather than relying solely on sender-based blocking.
Security note. Blocking a sender address alone may not stop spoofed messages that only imitate the visible From address. For impersonation attacks, we recommend using Anti-Phishing Policies, Spoof Intelligence, and domain authentication controls (SPF, DKIM, and DMARC).
Typical Security Operations Workflow
Note that in many Microsoft 365 environments, sender blocking is performed as part of an incident response workflow rather than as a standalone admin task.
Here is how a common process looks like:
1. A user reports a suspicious/phishing message using Microsoft User Submissions. 2. A security analyst investigates the message in Threat Explorer/Explorer. 3. The sender domain, address, or campaign indicators are validated. 4. The sender is added to the Tenant Allow/Block List to prevent future delivery.
Microsoft Defender for Office 365 provides investigation tools that help you to identify malicious senders, affected recipients, message disposition, and related indicators before enforcing a block action.
Configure Tenant Allow/Block List Rule in Microsoft 365 Defender
The preferred way to block list specific senders and/or domains is to use the Tenant Allow/Block List feature in Microsoft 365 Defender.
Add Blocked Senders in Microsoft Defender portal
The security administrator can use the Microsoft Defender portal to manage this block list.
You can add multiple domains/email addresses to the Tenant Allow/Block List. Keep in mind that the number of entries depends on the entry type and Microsoft 365 service constraints. In the UI, you can enter multiple values separated by commas or new lines.
To block these senders completely, select ‘Never expires‘ in ‘Remove block entry after‘.
Click Add to save the block list.
To add more addresses, repeat from step 4.
Note. There are different limits in Microsoft 365: they depend on whether you are adding domains, individual email addresses, or bulk entries through PowerShell. In case you’re performing large-scale blocking, we recommend using PowerShell for bulk operations (in such scenario, you will have an option to prepare input data (for example, from CSV file) and process it).
Method
Entry limit
Tenant Allow/Block List (UI)
Varies by type
Tenant Allow/Block List (PowerShell)
Depends on Microsoft 365 licensing and service limits. Check current Microsoft documentation before large-scale deployments.
Anti-Spam Policy block list
1000 entries
Note that current limits may change over time. You should check the latest Microsoft documentation before large-scale deployments.
Manage Tenant Allow/Block Lists with PowerShell
Note. Tenant Allow/Block List cmdlets are service-backed Microsoft 365 Defender APIs exposed through the ExchangeOnlineManagement module. Their parameters, behavior, output structure, and available properties may change over time due to module updates/backend service changes. Before using these cmdlets in production scripts, you should validate them against the latest Microsoft documentation and test them in your environment.
You can use PowerShell cmdlets from the ExchangeOnlineManagement module to manage the Tenant Allow/Block lists.
Note that the cmdlet accepts both domains and email addresses in the Entries parameter. The service determines the appropriate sender entry type based on the supplied value.
Note that removal behavior depends on exact match of the stored entry (domain vs email). Keep in mind that wildcard removal is not supported!
A sender blocked through Tenant Allow/Block List may receive an NDR similar to:
Remote server returned โ550 5.7.703 Your message canโt be delivered because messages to <email address>; are blocked by your organization using Tenant Allow Block List. For more information please go to https://go.microsoft.com/fwlink/?linkid=2237642. AS(8910)โ
Block Unwanted Senders in Microsoft with Anti-Spam Policy
Anti-spam policies in Microsoft Defender for Office 365 are used to check and filter incoming email messages based on spam confidence, reputation, and policy rules. Anti-spam policies regulate how messages are classified and handled (unlike Tenant Allow/Block List, which enforces a direct block).
Key difference:
Tenant Allow/Block List provides direct sender blocking and is generally preferred for security-driven sender/domain blocking cases.
Anti-spam policy is used for classification-based filtering (it can quarantine/mark as spam, and not always hard blocking)
Configure Anti-Spam Policy in Microsoft 365 Defender
Click Edit allowed and blocked senders and domains on the flyout that appears.
Click the โManage sender(s)โ or โBlock domainsโ depending on whether you want to block specific e-mail addresses or entire email domains.
Add the blocked senders and domains and save the policy. Note. You can add up to 1000 entries in the block list.
Click Close.
Based on multiple signals (machine learning, sender reputation, and policy rules), messages may be classified as spam/high confidence spam. Messages can be moved to quarantine, delivered to Junk Email, or blocked outright depending on the anti-spam policy setup.
In some scenarios, post-delivery protection mechanisms such as Zero-hour Auto Purge (ZAP) may re-evaluate previously delivered messages and remove/quarantine them retroactively.
Note. In Microsoft 365 the spam classification is not static. Because of post-delivery protection, the final message disposition can change after delivery mechanisms.
Using Exchange Mail Flow Rules to Block Senders
Exchange Online Mail flow rules (formerly known as transport rules) can be used to apply specific actions to messages as they flow through your Exchange organization. In this example, we will use the mail flow rules to reject messages from unwanted senders.
Keep in mind that large numbers of transport rules may increase admin complexity and are generally harder to maintain than centralized Tenant Allow/Block Lists.
Important. Note that transport rules are a legacy mail flow control mechanism in Exchange Online. These rules are usually used for conditional routing/compliance cases (rather than primary email blocking). In most security scenarios, Tenant Allow/Block List and Microsoft Defender policies take precedence.
How to Block Senders in Outlook
Microsoft 365 users can block unwanted senders directly from their Outlook app (whether it is a desktop app or Outlook Web App).
Note. In case a sender is on the user’s Safe Senders list, messages from them will bypass the Blocked Senders list. You need to check Safe Senders list to find out if blocked emails are still being delivered.
Outlook Desktop App Blocked Senders
Connect to your mailbox using Outlook (or sign-in Outlook web app)
Go to the Home tab on the ribbon and select Junk > Junk E-mail Options.
Navigate to the Blocked Senders tab and add the domains and/or e-mail address you want to block list.
Emails from blocked senders in Outlook are handled at the mailbox level and may be moved to Junk Email by the Outlook client. Keep in mind that this is a user-level setting, it doesn’t override server-side filtering/organizational security policies.
Note. Keep in mind that blocked senders list is a client-side mailbox setting, and this setting can be overridden/ignored depending on Microsoft 365 security policies, Exchange transport rules, and Defender filtering.
The recommended method is to use the Tenant Allow/Block List in the Microsoft Defender portal. It provides the highest priority enforcement and ensures that messages from specified domains or email addresses are blocked at the service level.
I enjoy technology and developing websites. Since 2012 I'm running a few of my own websites, and share useful content on gadgets, PC administration and website promotion.
strange, it’s not deleting the address I entered in the list, still just sending it to Junk. It is configured to delete a specified address but our end user is still receiving it in his Junk folder.
John Whalley
3 years ago
I’m familiar with blocking a full domain name (@example.com) in Office 365 and use it quite often. Before I take the full leap to using white-lists instead of black-lists, I’d like to try blocking most robo-emails who append random characters after the primary name (@examplekgclddd.com). Is it possible to block a partial domain name (@example) to accomplish this?
strange, it’s not deleting the address I entered in the list, still just sending it to Junk. It is configured to delete a specified address but our end user is still receiving it in his Junk folder.
I’m familiar with blocking a full domain name (@example.com) in Office 365 and use it quite often. Before I take the full leap to using white-lists instead of black-lists, I’d like to try blocking most robo-emails who append random characters after the primary name (@examplekgclddd.com). Is it possible to block a partial domain name (@example) to accomplish this?