Blog/ Outlook how-tos

How to Block a Domain in Microsoft 365 for the Whole Tenant

Nafiul HasanNafiul Hasan· 9 min read
Illustration of an email domain being intercepted at the Microsoft 365 tenant edge before it can reach any mailbox, representing an admin blocking a domain tenant-wide

The short answer

Add the domain as a block entry in the Tenant Allow/Block List (Microsoft 365 Defender portal, Domains & addresses tab) or create an Exchange mail flow rule that rejects mail from that domain. Both apply tenant-wide, unlike a per-user Block Sender, which only hides mail from one mailbox. Entries take effect within about five minutes.

Block a domain Microsoft 365 admin-wide with the Tenant Allow/Block List or a mail flow rule — not the per-user block, which only covers one mailbox.

On this page
  1. 01Before you start
  2. 02Block the domain in the Tenant Allow/Block List
  3. 03Or reject it with a mail flow rule
  4. 04Where each block point sits in the mail path
  5. 05What to do when it doesn't work
  6. 06A faster way

To block a domain in Microsoft 365 admin-wide, add it as a block entry in the Tenant Allow/Block List — Microsoft 365 Defender portal, Email & collaboration, Policies & rules, Threat policies, Tenant Allow/Block Lists, Domains & addresses tab. That one setting stops mail from that domain reaching any mailbox in your organization, not just yours.

This is a different action from clicking Block Sender in Outlook. That button only edits one person's Junk Email settings — it does nothing for the other 40, 400 or 4,000 mailboxes still receiving the same spam or spoof campaign. If a domain is targeting the whole company, the tenant-level tools are the ones that actually stop it.

Before you start#

You'll need admin rights: Global Administrator, Security Administrator, or Exchange Administrator all cover both the Tenant Allow/Block List and Exchange mail flow rules, so any of those gets you through the whole process below.

Get the exact domain from a message header or a message trace, not from the sender's display name — a spoofed message can show any display name it wants, but the domain in the actual From address is harder to fake convincingly.

  • Decide whether you need the base domain, its subdomains, or both — a block entry for contoso.com does not automatically cover marketing.contoso.com. That needs a separate wildcard entry (more on this below).
  • Without Defender for Office 365, a tenant can hold up to 500 domain and address block entries. Defender for Office 365 Plan 1 raises that to 1,000; Plan 2 raises it to 10,000. Blocking a handful of spam or spoof domains won't come close to any of these.
  • Know that this is bidirectional before you turn it on — see the warning further down.

Block the domain in the Tenant Allow/Block List#

This is Microsoft's recommended method, and the one to reach for first for almost any spam or phishing domain.

  1. 1

    Open the Tenant Allow/Block List

    Sign in to the Microsoft 365 Defender portal at security.microsoft.com, then go to Email & collaboration, Policies & rules, Threat policies, Tenant Allow/Block Lists — or jump straight there at security.microsoft.com/tenantAllowBlockList.

  2. 2

    Select the Domains & addresses tab

    Confirm you're on that tab specifically. The same page also has separate tabs for spoofed senders, files, URLs and IP addresses, and an entry added on the wrong one won't behave the way you expect.

  3. 3

    Select Add, then Block

    A flyout titled "Block domains & addresses" opens for the new entry.

  4. 4

    Enter the domain

    Type the domain, one per line, up to 20 at a time. Add the bare domain (contoso.com) and, as a separate line, the wildcard form (*.contoso.com) if you also want its subdomains covered — Microsoft treats these as two distinct entries, not one.

  5. 5

    Set an expiration

    Choose 1 day, 7 days, 30 days (the default), a specific date up to 90 days out, or Never expire. An expiring entry is the safer choice for a domain that could turn out to be legitimate again later.

  6. 6

    Save it

    Select Add. The block is enforced tenant-wide within about five minutes — no mailbox restart, no PowerShell session required.

Or reject it with a mail flow rule#

The Tenant Allow/Block List is the default, but a mail flow (transport) rule is worth setting up instead when you want a specific bounce message worded for your organization, want the block to apply only to certain recipients or with an exception, or are managing a hybrid environment where the same block needs to reach on-premises routing too.

  1. 1

    Open Mail flow rules

    In the Exchange admin center at admin.exchange.microsoft.com, go to Mail flow, then Rules.

  2. 2

    Create a new rule

    Select "+ Add a rule", then "Create a new rule".

  3. 3

    Set the condition to the sender's domain

    Under "Apply this rule if", choose "The sender", then "domain is", and enter the domain you're blocking.

  4. 4

    Set the action to reject or delete

    Under "Do the following", choose "Block the message", then either "Reject the message and include an explanation" (the sender gets a bounce, error code 550 5.7.1) or "Delete the message without notifying anyone" (silent).

  5. 5

    Save it and check the priority

    Save the rule, then check where it sits relative to your other mail flow rules. A higher-priority rule that stops processing further rules can prevent this one from ever running against a message it would otherwise have caught.

Where each block point sits in the mail path#

These three tools live at different points in the same pipeline, which is why mixing them up produces confusing results. Think of it as three checkpoints — the tenant edge, the transport rules, and the individual mailbox — and mail that clears the first two still has to get past whatever exists at the third.

Diagram of three checkpoints in the Microsoft 365 mail path — the tenant-level Allow/Block List, an Exchange mail flow rule, and a per-mailbox Block Sender setting — showing where each one can intercept a message before it reaches an inbox
The same domain gets a different outcome depending on which checkpoint stops it.
MethodWhere you set itScopeWhat the sender seesHow to undo it
Tenant Allow/Block ListMicrosoft 365 Defender portal, Tenant Allow/Block ListsWhole tenant, every mailboxNo bounce — mail is marked high-confidence phishing and quarantinedDelete or edit the entry; takes effect within ~5 minutes
Mail flow (transport) ruleExchange admin center, Mail flow > RulesWhole tenant, every mailboxBounce (550 5.7.1) if set to reject, or silent deleteDisable or delete the rule
Block Sender (Outlook)Outlook ribbon or right-click, Junk > Block SenderOne mailbox onlyMail routes to that user's Junk Email folder; other mailboxes unaffectedRemove the address from that user's Blocked Senders list

What to do when it doesn't work#

A blocked domain that still lands in someone's inbox almost always traces back to one of the following. Work through them in order before assuming the feature itself is broken.

  • Subdomains weren't covered — a block entry for contoso.com does not reach mail.contoso.com or billing.contoso.com. Add the wildcard *.contoso.com as a second, separate entry.
  • The entry expired — the default is 30 days. Check the "Remove on" column on the Domains & addresses tab; an expired entry is gone quietly, not still working quietly.
  • It's a lookalike domain, not the one you blocked — c0ntoso.com, contoso-billing.com and contoso.co are different domains to Exchange even when a person skims past the difference. Block each variant you actually see, and check the Spoofed senders tab separately if the attacker is forging your own domain in the From address.
  • A higher-priority mail flow rule let it through first — rules run in priority order, and one that matches earlier and stops further processing can skip your reject rule entirely. Check the order under Mail flow > Rules.
  • The message was released from quarantine — a Tenant Allow/Block List block sends mail to quarantine as high-confidence phishing, and depending on your quarantine policy, another admin or the recipient may have released it manually.
  • Only the address was blocked, not the domain — a block entry or Block Sender action for [email protected] does nothing for [email protected]. Confirm the entry is on the domain, not a single address.
  • Run a message trace — Exchange admin center, Mail flow, Message trace shows which filter actually processed the message, rather than guessing from what's sitting in the inbox.

This also blocks outbound mail to that domain

A domain block entry in the Tenant Allow/Block List is bidirectional: anyone in your organization who tries to send to that domain gets a non-delivery report with the error 550 5.7.703. If there's any chance the domain includes a real vendor, customer or partner later, set an expiring block rather than Never expire.

A faster way#

Tenant-level blocking is the right tool for a domain you can name, but a lookalike spam or cold-outreach campaign that rotates through a new domain every week turns "block the domain" into a standing chore — someone has to notice the new one, open the Defender portal, and add another entry before the last one expires.

AI Emaily's spam protection runs underneath the mailboxes you connect and filters on sender behavior and reputation rather than a static list someone has to keep current, so a freshly rotated domain doesn't get a free pass just because it's new. It sits alongside your tenant's existing Allow/Block List and mail flow rules rather than replacing them — Exchange still owns the hard reject at the edge; AI Emaily handles the judgment calls on everything that hasn't been blocked yet. We build AI Emaily.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Stop chasing every new spam domain by hand

AI Emaily filters spam and cold outreach by sender behavior, not a list you have to keep current — connect your Microsoft 365 mailbox and see it on your own inbox during the 7-day trial.

  • 7-day free trial
  • Cancel anytime
  • Every provider