How to Block Emails From a Whole Domain, Not One Address

The short answer
To block every email from a domain, create a Gmail filter with from:*@domain.com, add the domain to Outlook's blocked-senders list, or add it to Microsoft 365's Tenant Allow/Block List. The critical detail most guides miss: none of these block subdomains by default. Microsoft 365 requires *.domain.com; Gmail and Outlook each need a separate rule or entry.
How to block a whole email domain in Gmail, Outlook, and Microsoft 365 — and why subdomains need a separate entry on most platforms.
On this page
You blocked the sender. Then another one from the same company. Then two more. At some point, blocking individual addresses becomes a maintenance job that scales in favour of the sender, not you — as long as they own a domain, they can put any name in front of it.
Blocking the whole domain is the right move when a single source keeps generating new addresses. The mechanics are straightforward, but the syntax differs between Gmail, personal Outlook, and Microsoft 365 — and the behaviour around subdomains is where most guides get it wrong. Whether a block on domain.com also catches mail from news.domain.com or b2.domain.com depends entirely on which provider you are on and how you entered the rule.
The short answer#
In Gmail, open the filter creator and enter *@domain.com in the From field. In personal Outlook or Outlook.com, add the domain to your Blocked Senders list. In Microsoft 365, add the domain to the Tenant Allow/Block List in the Defender portal. All three approaches stop mail from that exact domain.
The subdomain question is where they diverge. Gmail's filter does not match subdomains: *@domain.com will not catch mail from mail.domain.com or news.domain.com. Outlook's blocked-senders entry behaves the same way. Microsoft 365's Tenant Allow/Block List also stops only the exact domain unless you use the *.domain.com wildcard syntax — that is explicitly documented as required for subdomain coverage. The platform differences table below gives the full breakdown.
Before you block#
Domain blocks are wide. A single rule affects every address the domain has ever had and ever will have, including addresses you might want. Before you apply one, spend thirty seconds reading the From header on an actual message rather than guessing from the sender display name.
In Gmail, open a message, click the three-dot menu at the top right, and select Show original. In Outlook, open the message, go to File, then Properties, and read the Internet headers block. The value on the From line — specifically the domain after the @ symbol — is what you are blocking. That is often different from the company's website domain: marketing sends from em.company.com, support sends from helpdesk.zendesk.com, and direct sales is the only thing actually on company.com.
Also consider what else lives on that domain. If you block a domain that carries both sales pitches and order confirmations, the confirmations go too. If you are confident the domain exists only to reach you with mail you do not want, proceed.
Steps by provider#
Follow the steps for your email provider. The underlying logic is the same — you are telling your client or your admin system to treat a pattern as the sender rule, not a single address — but the interface and the exact input format differ.
- 1
Gmail: create a filter with from:*@domain.com
Click the search bar at the top of Gmail. Select the filter icon on the right side of the bar (Show search options). In the From field, enter *@domain.com — include the asterisk. Click Create filter. On the next screen, tick Delete it to remove matching messages permanently, or Mark as spam to route them to the Spam folder. To apply the rule to messages already in your inbox, tick Apply filter to matching conversations before saving. Gmail will process the filter immediately for future messages.
- 2
Outlook.com and new Outlook: add to Blocked Senders
Go to Settings (the gear icon, top right) and select Mail, then Junk email. Under Blocked senders and domains, type the domain — you can enter it as example.com or @example.com — and press Enter or click the plus icon. Select Save. In the classic Outlook desktop application, go to Home, then Junk, then Junk Email Options, and open the Blocked Senders tab. Click Add, enter the domain, and click OK. Mail matching the entry is moved to the Junk Email folder rather than deleted. Important: this approach does not cover subdomains — see the table below for the workaround.
- 3
Microsoft 365 (admin): Tenant Allow/Block List
Open the Microsoft Defender portal at security.microsoft.com. Go to Email and collaboration, then Policies and rules, then Threat policies, then Tenant Allow/Block Lists. On the Domains and addresses tab, click Add, then Block. Enter the domain on its own line. To also block all subdomains, add a second entry on the next line using the wildcard syntax: *.domain.com. Set an expiry — the default is 30 days — or choose Never expire for a permanent block. Click Add. Messages matching a block entry are quarantined as high-confidence phishing, not just moved to junk. This requires Security Administrator or Organization Management permissions.
Provider differences at a glance#
The table below summarises the exact input format for each method and whether it covers subdomains. Verify these against vendor documentation before relying on them, as interface details can change.

| Provider and method | Exact syntax | Subdomain coverage |
|---|---|---|
| Gmail filter (From field) | *@domain.com | No — mail from sub.domain.com is not matched |
| Gmail workaround (Has the words field) | domain.com | Partial — catches subdomains but may match unrelated content |
| Outlook / Outlook.com blocked senders | example.com or @example.com | No — mail from sub.example.com arrives unchanged |
| Outlook rule (Sender address includes) | example.com | Yes — string match catches the domain and any subdomain |
| Microsoft 365 Tenant Allow/Block List | domain.com | No — blocks the exact domain only |
| Microsoft 365 Tenant Allow/Block List (wildcard) | *.domain.com | Yes — documented wildcard; blocks all subdomains |
When the block doesn't work#
If new mail from the same source keeps arriving after you set a domain block, the cause is almost always one of three things.
The sender is using a subdomain. Open the raw headers on a message that slipped through and check the From domain. If you blocked example.com and the mail is coming from b2.example.com or news.example.com, the block did not miss — it worked exactly as documented. In Gmail, add a second filter for *@b2.example.com. In personal Outlook, switch from the blocked-senders list to a rule: go to Settings, Mail, Rules, add a condition for Sender address includes, and enter the root domain. That string-match approach catches any subdomain automatically.
The sending domain is different from what you blocked. Marketing platforms often deliver on behalf of a company using their own infrastructure. A block on example.com has no effect on mail sent from em.example.com, hs1.example.com, or the platform's own shared domain. You need to block the actual sending domain shown in the headers, not the brand's website.
The filter was saved but is not processing. In Gmail, filters apply only to messages received after the filter was created, unless you checked Apply filter to matching conversations. In Outlook, new rules added in the web interface can take a few minutes to take effect in the desktop app.
The subdomain gap is the most common reason a domain block fails
A faster way to handle this continuously#
A domain block is the right fix for a sender you have already identified. What it does not solve is the volume problem: each new subdomain variant, each rotating sending domain from the same source, needs its own entry. A persistent sender can outlast your willingness to maintain a growing list.
AI Emaily's cold-email filter works at the sender-behaviour and domain level rather than matching one address at a time. A domain that keeps generating unwanted mail accumulates a signal, and subdomain variants of it inherit that signal — without you having to add each one as a new entry. The filter does not require you to identify every subdomain in advance. We build AI Emaily. If your block list is short and stable, the manual approach above is sufficient. If it has been growing for months with the same sources reappearing under new subdomains, the continuous filter is the mechanism worth using.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.