You can use the Exchange Admin Center (EAC) web interface to create and edit an Exchange transport rule. In this example, we will create a transport rule in EOL.
About mail flow rules
Exchange Transport Rules (ETRs), also known as Mail Flow rules, are used to select and apply various actions to messages based on specific criteria as they flow through your Exchange organization. Transport rules can be used to process mail flow in both on-premises Exchange Server 2019/2016/2013 and Exchange Online (EOL).
Note. In modern Microsoft 365 environments, many compliance-related cases that were previously handled by mail flow rules have moved to Microsoft Purview and Microsoft Defender for Office 365. Mail flow rules are now primarily used for message routing, basic blocking, and simple transformations rather than compliance enforcement.
Rule evaluation order and processing behavior
Keep in mind that in Exchange Online (EOP), mail flow rules are processed in a strict priority order. Here are the main characteristics:
- Rules are evaluated from lowest number (highest priority) to highest number (lowest priority)
- Each message is evaluated sequentially against all applicable rules
- If a rule has “Stop processing more rules” enabled, no further rules are evaluated
- Multiple matching rules can apply unless processing is explicitly stopped
Rule conflict and precedence behavior
If you have a situation when multiple transport rules match the same message:
- All matching rules are applied unless a rule stops processing
- Actions are cumulative (unless they conflict, e.g., reject vs modify)
- Reject/block actions take precedence and terminate message processing
- More specific conditions should be placed at higher priority (lower number)
Where mail flow rules sit in the Microsoft 365 email security pipeline
Note that in Microsoft 365, mail flow rules (Exchange Transport Rules) operate within the Exchange Online Protection (EOP) transport pipeline. Here is how a simplified message processing flow looks like:
- Connection filtering (IP reputation, anti-spam pre-filtering)
- Anti-malware scanning
- Exchange Online Protection (EOP) transport processing
- Mail flow rules (Transport Rules)
- Microsoft Defender for Office 365 policy evaluation (Safe Links, Safe Attachments, advanced protection)
- Delivery to mailbox
- Post-delivery protection actions (quarantine, ZAP, retroactive actions)
Mail flow rules are evaluated during transport. It means that:
- they act before final mailbox delivery
- they can modify, block, or redirect messages before they are stored
- they do not replace post-delivery security controls
Important. Note that mail flow rules operate in the transport layer and are not a substitute for content-based security scanning performed by Microsoft Defender for Office 365. Defender policies can still evaluate and act on messages after transport rule processing, including post-delivery remediation.
Elements of Exchange mail flow rule
The Exchange mail flow rule consists of four elements:
- Conditions โ allows you to define criteria for the selection of emails to which rules are to be applied. For example, sender/recipient email address or domain, message direction, email subject, etc.
- Actions โ action to be taken on messages when a configuration condition is met.
- Exceptions โ allows you to specify attributes of an email message for which you want to skip the actions.
- Mode โ whether to apply the rule immediately (Enforce) or run it in test mode first (Test with/without Policy Tips).
Important. In modern Microsoft 365 architecture, mail flow rules are no longer the primary enforcement layer for compliance and security policies. Note that features such as Data Loss Prevention (DLP), sensitivity labels enforcement, encryption policies, and insider risk detection are now handled by Microsoft Purview and Microsoft Defender for Office 365 policies.
Exchange Online vs On-Premises behavior differences
Mail flow rules behave differently depending on whether you use Exchange Online/on-premises Exchange Server.
For Exchange Online (Microsoft 365)
- Rules are processed in a distributed cloud environment (EOP)
- Changes may take time to propagate across datacenters (typically minutes, sometimes longer)
- Rule evaluation is subject to service-side throttling and backend optimization
- Some actions depend on Defender for Office 365 or Purview services
For on-premises Exchange Server
- Rules are evaluated locally on Transport servers
- Changes take effect immediately after AD/transport service propagation
- There is no dependency on cloud security services
- You have a full control over transport pipeline behavior
Hybrid environments
Keep in mind that in hybrid Exchange deployments:
- Mail may pass through both on-prem transport and Exchange Online Protection (EOP)
- Rule evaluation depends on mail routing path (inbound vs outbound vs internal relay)
- Some rules may be evaluated twice (once on-prem, once in EXO)
- Misconfigured connectors can cause inconsistent rule behavior
Rule propagation and latency considerations
Note that in Exchange Online, transport rule changes are not always immediate:
- Typical propagation delay is 1โ10 minutes
- In large tenants delay can be up to 30 minutes
- Cached routing decisions may temporarily ignore new rules
As the best practice, we recommend you to wait before testing new rules in production and use Message Trace to validate rule application.
Creating a mail flow rule
Note. When creating multiple transport rules, you should always consider rule priority. Keep in mind that incorrect ordering may result in:
- bypassed blocking rules
- unintended message modifications
- conflicting actions between rules
We recommend you to assign the most restrictive rules the highest priority.
Let’s create a simple mail flow rule that prevents the organization from sending mail to external mailboxes in the @gmail.com domain.
- Sign-in to Exchange Admin Center https://admin.exchange.microsoft.com/
- Navigate to Mail flow > Rules;
- Click Add a rule;

- Create a new rule or select one of the preconfigured ETR templates, including add an email disclaimer, filter message by size, send copy message for review to moderator, modify messages, etc.
- We will create a new clean rule from scratch. Select Create a new rule;
- Specify rule name: Block outgoing email to Gmail;
- Apply this rule if: The recipient > domain is > gmail.com;
Do the following: Block the message > reject the message and include an explanation > ‘Not authorized recipient’

- Then select the rule settings. If you want to apply the transport rule immediately, select Rule Mode > Enforce. You can also enable the Stop processing more rules option.

- Then enable the new transport rule in EAC.
Blocking a single external domain (such as gmail.com) using mail flow rules is a simplified approach and should not be used as a primary security control in modern Microsoft 365 environments.
However, it still remains valid in specific cases, such as:
- rapid incident containment (temporary blocking during an investigation)
- internal compliance/policy enforcement in small/controlled environments
- simple routing/organizational restrictions where advanced security policies are not required
When mail flow rules are still appropriate?
Despite modern alternatives in Microsoft Purview and Defender for Office 365, transport rules are still useful in such cases:
- you need immediate message-level enforcement without policy dependency
- the requirement is purely deterministic (e.g., block/allow based on domain or header)
- you operate in on-prem/hybrid environments without full Defender integration
- you need predictable, transparent rule execution for troubleshooting purposes
Note that in modern Microsoft 365 environments, you generally should not use domain-based blocking as the primary security mechanism (however, it may still be acceptable as a supplementary/temporary control depending on the case).
Here are the recommended modern approaches instead of simple domain blocking:
- Outbound anti-spam policies in Microsoft Defender for Office 365 (restrict/control external email flow at tenant level)
- Tenant-wide external access restrictions (Microsoft 365 admin center โ Org-wide settings โ External communications)
- Policy-based controls in Microsoft Defender for Office 365 for advanced outbound filtering and risk-based decisions
Here is a comparison table:
| Method | Status in 2026 | Use case |
|---|---|---|
| Mail flow rule (block domain) | Legacy/limited use | Simple blocking/lab environments |
| Outbound spam policy | Recommended | Tenant-level external mail control |
| Defender for Office 365 policies | Recommended | Security-driven filtering and risk analysis |
Also note that while mail flow rules can still block specific domains, we recommend using outbound anti-spam policies/tenant-wide restrictions in Microsoft Defender for Office 365 for more advanced and secure control cases.
Note. After 2023, DLP-related conditions and actions in mail flow rules can only be created and managed through DLP policies in Microsoft Purview Compliance Center.
What mail flow rules are still used for in 2026?
Despite the shift toward Microsoft Purview and Microsoft Defender for Office 365, you can still use mail flow rules for operational cases that require deterministic message processing.
Here are the common valid use cases:
- When you need to add disclaimers/legal banners to outgoing emails
- Modifying message routing (e.g., redirecting, forwarding, or journaling)
- Tagging/stamping messages with headers for downstream systems
- Simple conditional blocking based on sender/recipient/keywords
- Internal message normalization (subject prefixing, footer enforcement)
It is important to note that you should not consider these cases as security enforcement mechanisms in modern Microsoft 365 architecture, but rather message processing and transport control functions.
Use PowerShell to manage Exchange transport rules
Because mail flow rules still play an important role in message processing, you can manage and automate them using PowerShell in both hybrid and cloud environments.
You can use PowerShell to manage Exchange transport rules. The following cmdlets are used:
- Get-TransportRule
- New-TransportRule
- Remove-TransportRule
- Enable-TransportRule
- Disable-TransportRule
Note. In Exchange Online environments, typically you can perform transport rule management using the ExchangeOnlineManagement PowerShell module. However, keep in mind that modern cmdlets are REST-backed and may require Connect-ExchangeOnline authentication.
Keep in mind that in Exchange Online, PowerShell cmdlets for transport rules are executed against a distributed service layer. As a result, changes may not reflect instantly due to backend sync.
Let’s use PowerShell to create a similar rule that will block outgoing e-mail to a specific domain:
New-TransportRule -Name "Block to test.com" -RecipientDomainIs "test.com" -RejectMessageEnhancedStatusCode "5.7.1" -RejectMessageReasonText "not allowed recipient" -Priority 0 -Enabled $true

You can use the Priority parameter to specify the order in which transport rules are processed. The rule with the Priority 0 parameter has the highest priority.
Disable mail flow rule
Get-TransportRule "Block to test.com"| Disable-TransportRule
Checking rule priority
Get-TransportRule | Sort-Object Priority | Select Name,Priority
Checking rules
Try to send an email to a domain that is blocked. The sender should receive an NDR with code 550 5.7.1_ETR and the email will not be delivered to the recipient.
Note that in Microsoft 365, transport rule evaluation may be overridden/supplemented by Microsoft Defender for Office 365 policies and Microsoft Purview compliance policies (depending on config priority and policy scope).
If you trace an email in the Exchange transport logs, you can see which transport rule was applied to the email:
Reason: [{LED=550 5.7.1 TRANSPORT.RULES.RejectMessage; the message was rejected by organization policy};
Transport rule: ‘Block outgoing email to Gmail’

What are Exchange mail flow rules?
Exchange mail flow rules (also called Exchange Transport Rules) are conditions-based rules used to process email messages as they pass through an organization. They can modify, block, redirect, or tag messages based on criteria such as sender, recipient, domain, or message content. They are used in both on-premises Exchange and Microsoft 365 environments.
Where are mail flow rules configured?
Mail flow rules are configured in the Exchange Admin Center under Mail flow โ Rules. Administrators can create, edit, enable, and prioritize rules through this interface or via PowerShell.
Where do mail flow rules sit in the email processing pipeline?
In Exchange Online Protection, mail flow rules are evaluated after anti-spam/anti-malware filtering but before final delivery.
Typical flow:
- Connection filtering
- Anti-malware scanning
- EOP transport processing
- Mail flow rules
- Microsoft Defender for Office 365 policies
- Delivery to mailbox
- Post-delivery actions
What are the main components of a mail flow rule?
A transport rule consists of:
- Conditions โ define when the rule applies (sender, domain, keywords, etc.)
- Actions โ what happens when conditions match (block, redirect, modify, etc.)
- Exceptions โ conditions that exclude messages from the rule
- Mode โ enforce or test mode (with or without policy tips)
How long do mail flow rules take to apply?
In most cases:
- 1โ10 minutes in Exchange Online
- Up to 30 minutes in large tenants
- On-premises changes apply faster after propagation



Hi Cyril, is it possible to block sending of emails generated from a test environment? Thanks