Create Safe Sender Lists In Office 365
In brief
The article date was updated and now links to instructions for using mail flow rules to bypass spam filtering, while directing administrators to use the documented conditions and actions to safely allow senders.
What Defender admins need to know
Review the updated guidance when configuring sender allow rules; no required administrator action is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Mail flow rules in Exchange Online use conditions and exceptions to identify messages, and actions to specify what should be done to those messages. For more information, see Mail flow rules (transport rules) in Exchange Online.
To create a mail flow rule that bypasses spam filtering, follow the steps in Use mail flow rules to set the spam confidence level (SCL) in messages. To safely allow senders, use the conditions and actions described in this section.
The following example assumes you need email from contoso.com to skip spam filtering. Configure the following settings:
- Apply this rule if (condition): The sender > domain is > contoso.com.
@@ -13,7 +13,7 @@ ms.custom: - seo-marvel-apr2020 description: Admins can learn about the available and preferred options to allow inbound messages to Microsoft 365. ms.service: defender-office-365-ms.date: 07/03/2026+ms.date: 07/24/2026 appliesto: - ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Built-in security features for all cloud mailboxes</a> - ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>@@ -61,6 +61,8 @@ Only consider other allow methods (mail flow rules, Outlook Safe Senders, IP All Mail flow rules in Exchange Online use conditions and exceptions to identify messages, and actions to specify what should be done to those messages. For more information, see [Mail flow rules (transport rules) in Exchange Online](/Exchange/security-and-compliance/mail-flow-rules/mail-flow-rules). +To create a mail flow rule that bypasses spam filtering, follow the steps in [Use mail flow rules to set the spam confidence level (SCL) in messages](/exchange/security-and-compliance/mail-flow-rules/use-rules-to-set-scl). To safely allow senders, use the conditions and actions described in this section.+ The following example assumes you need email from contoso.com to skip spam filtering. Configure the following settings: 1. **Apply this rule if** (condition): **The sender** \> **domain is** \> contoso.com. 