Microsoft Defender for Office 365
Email and collaboration

Outbound Spam Policies Configure

In brief

The page updates its description of outbound spam handling, records the 2021 history of the Automatic system-controlled forwarding setting, refreshes metadata, and adds links about delegated From addresses and Send As/on behalf permissions.

What Defender admins need to know

No administrator action is stated. Administrators get clearer context for interpreting the forwarding setting and managing delegated sending scenarios.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

In all organizations with cloud mailboxes, Microsoft 365 automatically checks outbound email messages for spam and unusual sending activity.

Outbound spam from a user in your organization typically indicates a compromised account. Suspicious outbound messages are marked as spam (regardless of the spam confidence level or SCL) and are routed through the high-risk delivery pool to help protect the reputation of the service (that is, to keep Microsoft 365 source email servers off IP block lists). Admins are automatically notified of suspicious outbound email activity and blocked users via alert policies.

Microsoft 365 uses outbound spam policies as part of your organization's overall defense against spam. For more information, see Anti-spam protection.

 Select one of the following actions from the **Automatic forwarding rules** dropdown list:

 - **Automatic - System-controlled**: This value is the default. This value is now the same as **Off - Forwarding is disabled**. When this value was originally introduced, it was equivalent to **On - Forwarding is enabled**. Over time, thanks toIn 2021, the principles of [secure by default](secure-by-default.md), the effect of this value was eventually changed to **Off - Forwarding is disabled** for all customers.new organizations and for existing organizations that weren't actively using the **Automatic - System-controlled** value. For existing organizations that were already using the value, it can remain equivalent to **On - Forwarding is enabled**. Because the behavior can differ by organization, configure **On - Forwarding is enabled** or **Off - Forwarding is disabled** instead of **Automatic - System-controlled**. For more information, see [All you need to know about automatic email forwarding in Exchange Online](https://techcommunity.microsoft.com/blog/exchange/all-you-need-to-know-about-automatic-email-forwarding-in-exchange-online/2074888).
 - **On - Forwarding is enabled**: Automatic external email forwarding isn't disabled by the policy.
 - **Off - Forwarding is disabled**: All automatic external email forwarding is disabled by the policy.

Related content

How outbound spam policy limits apply to Send As and Send on behalf permissions

Inventory delegated From addresses for outbound spam policies

Troubleshoot outbound sending limits in Exchange Online

Remove blocked users from the Restricted entities page