Microsoft Defender for Office 365
Email and collaboration

Create Block Sender Lists In Office 365

In brief

The page date and terminology were updated, “High confidence spam” formatting was standardized, a Mail flow rules in Exchange Online link was added, and one SCL guidance paragraph was commented out.

What Defender admins need to know

No administrator action is stated. The added link provides a direct reference for mail flow rule guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.localizationpriority: medium description: Admins can learn about the available and preferred options to block inbound messages to Microsoft 365. ms.service: defender-office-365 ms.date: 07/03/24/2026 appliesto:

  1. Block entries for domains and email addresses (including spoofed senders) in the Tenant Allow/Block List.
  2. Outlook Blocked Senders (the Blocked Senders list in each mailbox that affects only that mailbox).
  3. Blocked sender lists or blocked domain lists in anti-spam policies.
  4. Exchange mail flow rules (also known as transport(transport rules).
  5. The IP Block List in the default connection filter policy.

The following sections describe each method in more detail.

Our number one recommended option for blocking mail from specific senders or domains is the Tenant Allow/Block List. For instructions, see Create block entries for domains and email addresses and Create block entries for spoofed senders.

Email messages from senders or domains that you block by using Tenant Allow/Block List entries are marked as highHigh confidence spam (SCL = 9). The anti-spam policy that detected the message for the recipient determines what happens to the messages. In the Standard and Strict preset security policies, high confidence spam messages are quarantined.

As an added benefit, users in the organization can't send email to these blocked domains and addresses. The message is returned in the following non-delivery report (also known as an NDR or bounce message): 550 5.7.703 Your message can't be delivered because messages to XXX, YYY are blocked by your organization using Tenant Allow Block List. The entire message is blocked for all internal and external recipients of the message, even if only one recipient email address or domain is defined in a block entry.

Use mail flow rules

Mail flow rules can also look for keywords or other properties in the unwanted messages. For more information about mail flow rules, see Mail flow rules in Exchange Online.

Regardless of the conditions or exceptions that you use to identify the messages, you configure the action to set the spam confidence level (SCL) of the message to 9, which marks the message as High confidence spam. For more information, see Use mail flow rules to set the SCL in messages.

Use the IP Block List in the default connection filter policy