How to Block a Domain in Microsoft 365 for the Whole Tenant

The short answer
Add the domain as a block entry in the Tenant Allow/Block List (Microsoft 365 Defender portal, Domains & addresses tab) or create an Exchange mail flow rule that rejects mail from that domain. Both apply tenant-wide, unlike a per-user Block Sender, which only hides mail from one mailbox. Entries take effect within about five minutes.
Block a domain Microsoft 365 admin-wide with the Tenant Allow/Block List or a mail flow rule — not the per-user block, which only covers one mailbox.
On this page
To block a domain in Microsoft 365 admin-wide, add it as a block entry in the Tenant Allow/Block List — Microsoft 365 Defender portal, Email & collaboration, Policies & rules, Threat policies, Tenant Allow/Block Lists, Domains & addresses tab. That one setting stops mail from that domain reaching any mailbox in your organization, not just yours.
This is a different action from clicking Block Sender in Outlook. That button only edits one person's Junk Email settings — it does nothing for the other 40, 400 or 4,000 mailboxes still receiving the same spam or spoof campaign. If a domain is targeting the whole company, the tenant-level tools are the ones that actually stop it.
Before you start#
You'll need admin rights: Global Administrator, Security Administrator, or Exchange Administrator all cover both the Tenant Allow/Block List and Exchange mail flow rules, so any of those gets you through the whole process below.
Get the exact domain from a message header or a message trace, not from the sender's display name — a spoofed message can show any display name it wants, but the domain in the actual From address is harder to fake convincingly.
- Decide whether you need the base domain, its subdomains, or both — a block entry for contoso.com does not automatically cover marketing.contoso.com. That needs a separate wildcard entry (more on this below).
- Without Defender for Office 365, a tenant can hold up to 500 domain and address block entries. Defender for Office 365 Plan 1 raises that to 1,000; Plan 2 raises it to 10,000. Blocking a handful of spam or spoof domains won't come close to any of these.
- Know that this is bidirectional before you turn it on — see the warning further down.
Block the domain in the Tenant Allow/Block List#
This is Microsoft's recommended method, and the one to reach for first for almost any spam or phishing domain.
- 1
Open the Tenant Allow/Block List
Sign in to the Microsoft 365 Defender portal at security.microsoft.com, then go to Email & collaboration, Policies & rules, Threat policies, Tenant Allow/Block Lists — or jump straight there at security.microsoft.com/tenantAllowBlockList.
- 2
Select the Domains & addresses tab
Confirm you're on that tab specifically. The same page also has separate tabs for spoofed senders, files, URLs and IP addresses, and an entry added on the wrong one won't behave the way you expect.
- 3
Select Add, then Block
A flyout titled "Block domains & addresses" opens for the new entry.
- 4
Enter the domain
Type the domain, one per line, up to 20 at a time. Add the bare domain (contoso.com) and, as a separate line, the wildcard form (*.contoso.com) if you also want its subdomains covered — Microsoft treats these as two distinct entries, not one.
- 5
Set an expiration
Choose 1 day, 7 days, 30 days (the default), a specific date up to 90 days out, or Never expire. An expiring entry is the safer choice for a domain that could turn out to be legitimate again later.
- 6
Save it
Select Add. The block is enforced tenant-wide within about five minutes — no mailbox restart, no PowerShell session required.
Or reject it with a mail flow rule#
The Tenant Allow/Block List is the default, but a mail flow (transport) rule is worth setting up instead when you want a specific bounce message worded for your organization, want the block to apply only to certain recipients or with an exception, or are managing a hybrid environment where the same block needs to reach on-premises routing too.
- 1
Open Mail flow rules
In the Exchange admin center at admin.exchange.microsoft.com, go to Mail flow, then Rules.
- 2
Create a new rule
Select "+ Add a rule", then "Create a new rule".
- 3
Set the condition to the sender's domain
Under "Apply this rule if", choose "The sender", then "domain is", and enter the domain you're blocking.
- 4
Set the action to reject or delete
Under "Do the following", choose "Block the message", then either "Reject the message and include an explanation" (the sender gets a bounce, error code 550 5.7.1) or "Delete the message without notifying anyone" (silent).
- 5
Save it and check the priority
Save the rule, then check where it sits relative to your other mail flow rules. A higher-priority rule that stops processing further rules can prevent this one from ever running against a message it would otherwise have caught.
Where each block point sits in the mail path#
These three tools live at different points in the same pipeline, which is why mixing them up produces confusing results. Think of it as three checkpoints — the tenant edge, the transport rules, and the individual mailbox — and mail that clears the first two still has to get past whatever exists at the third.

| Method | Where you set it | Scope | What the sender sees | How to undo it |
|---|---|---|---|---|
| Tenant Allow/Block List | Microsoft 365 Defender portal, Tenant Allow/Block Lists | Whole tenant, every mailbox | No bounce — mail is marked high-confidence phishing and quarantined | Delete or edit the entry; takes effect within ~5 minutes |
| Mail flow (transport) rule | Exchange admin center, Mail flow > Rules | Whole tenant, every mailbox | Bounce (550 5.7.1) if set to reject, or silent delete | Disable or delete the rule |
| Block Sender (Outlook) | Outlook ribbon or right-click, Junk > Block Sender | One mailbox only | Mail routes to that user's Junk Email folder; other mailboxes unaffected | Remove the address from that user's Blocked Senders list |
What to do when it doesn't work#
A blocked domain that still lands in someone's inbox almost always traces back to one of the following. Work through them in order before assuming the feature itself is broken.
- Subdomains weren't covered — a block entry for contoso.com does not reach mail.contoso.com or billing.contoso.com. Add the wildcard *.contoso.com as a second, separate entry.
- The entry expired — the default is 30 days. Check the "Remove on" column on the Domains & addresses tab; an expired entry is gone quietly, not still working quietly.
- It's a lookalike domain, not the one you blocked — c0ntoso.com, contoso-billing.com and contoso.co are different domains to Exchange even when a person skims past the difference. Block each variant you actually see, and check the Spoofed senders tab separately if the attacker is forging your own domain in the From address.
- A higher-priority mail flow rule let it through first — rules run in priority order, and one that matches earlier and stops further processing can skip your reject rule entirely. Check the order under Mail flow > Rules.
- The message was released from quarantine — a Tenant Allow/Block List block sends mail to quarantine as high-confidence phishing, and depending on your quarantine policy, another admin or the recipient may have released it manually.
- Only the address was blocked, not the domain — a block entry or Block Sender action for [email protected] does nothing for [email protected]. Confirm the entry is on the domain, not a single address.
- Run a message trace — Exchange admin center, Mail flow, Message trace shows which filter actually processed the message, rather than guessing from what's sitting in the inbox.
This also blocks outbound mail to that domain
A faster way#
Tenant-level blocking is the right tool for a domain you can name, but a lookalike spam or cold-outreach campaign that rotates through a new domain every week turns "block the domain" into a standing chore — someone has to notice the new one, open the Defender portal, and add another entry before the last one expires.
AI Emaily's spam protection runs underneath the mailboxes you connect and filters on sender behavior and reputation rather than a static list someone has to keep current, so a freshly rotated domain doesn't get a free pass just because it's new. It sits alongside your tenant's existing Allow/Block List and mail flow rules rather than replacing them — Exchange still owns the hard reject at the edge; AI Emaily handles the judgment calls on everything that hasn't been blocked yet. We build AI Emaily.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.