Blog/ Unwanted email by app

How to Stop Junk Email in Microsoft 365: User vs Admin

Nafiul HasanNafiul Hasan· 9 min read
Microsoft 365 junk email controls: Outlook Junk Email settings for users and Microsoft Defender anti-spam policies for admins

The short answer

On a Microsoft 365 work mailbox, you can block individual senders yourself in Outlook's Junk Email settings. Your employer's admin controls the anti-spam policy and Tenant Allow/Block List. If a block you set keeps letting mail through, a tenant-wide allow rule is overriding it — only an admin can fix that.

Stop junk email in Microsoft 365: what you can do yourself in Outlook, and what needs an admin in Microsoft Defender.

On this page
  1. 01Before you start: how the two-filter model works
  2. 02What you can do in your own mailbox
  3. 03What an admin can configure in Microsoft Defender
  4. 04Anti-spam policy vs Tenant Allow/Block List: choosing the right tool
  5. 05User vs admin: what each control does
  6. 06Why a blocked sender still arrives
  7. 07A faster way to stay ahead of junk

If you want to stop junk email in Microsoft 365, the first thing to understand is that two separate filters are in play — and only one of them is yours. The per-mailbox Junk Email filter in Outlook applies the blocked-senders list you set yourself. The tenant-level filter run by Exchange Online Protection applies your organization's anti-spam policy and Tenant Allow/Block List before mail ever reaches your mailbox.

Both filters work independently, and they can contradict each other. A sender you blocked can still reach your inbox if a tenant-wide allow entry clears it upstream — and nothing in Outlook shows you that. Knowing which layer controls what is the difference between fixing the problem and cycling through settings that have no effect.

Before you start: how the two-filter model works#

Mail arriving at a Microsoft 365 mailbox passes through Exchange Online Protection first. EOP applies the organization's anti-spam policy, checks the Tenant Allow/Block List, and evaluates sender authentication (SPF, DKIM, DMARC). Only mail that clears EOP is delivered to your mailbox. Once it arrives, Outlook's per-mailbox Junk Email filter applies your personal blocked-senders and safe-senders lists.

The EOP layer has higher authority. A tenant-level allow entry can clear a message regardless of your personal blocks. A tenant-level block quarantines a message regardless of your safe-senders list. Your Outlook Junk Email settings only act on mail that EOP has not already decided about.

This distinction matters for admins, too. The two tenant-level tools — the anti-spam policy and the Tenant Allow/Block List — handle blocked mail differently, and choosing the wrong one for the situation leaves real gaps.

What you can do in your own mailbox#

No admin rights are required for the following steps. Changes apply to your mailbox only and have no effect on your colleagues.

  1. 1

    Block a specific sender (Outlook for Windows or Mac)

    Right-click any message in your inbox. Select Junk, then Block Sender. The sender address is added to your Blocked Senders list and the message moves to Junk Email. All future mail from that address goes directly to Junk.

  2. 2

    Block an entire sending domain

    In Outlook on Windows, go to Home, then Junk, then Junk Email Options. On the Blocked Senders tab, click Add and type the domain name without an @ symbol — for example, spamsource.com. All mail from that domain to your mailbox is then moved to Junk Email.

  3. 3

    Block a sender in Outlook on the web

    Open the message, select the three-dot menu at the top of the message pane, then choose Block. In the confirmation dialog, select Block sender. The address is added to your Blocked Senders list under Settings, then Mail, then Junk Email.

  4. 4

    Review and manage your blocked-senders list

    In Outlook on the web, open Settings (the gear icon), search for Junk Email, and select Blocked senders and domains. Add or remove entries here. In classic Outlook on Windows, the same list is at Home, then Junk, then Junk Email Options, then Blocked Senders tab.

  5. 5

    Report a message as junk

    Select the message and choose Report at the top of the message pane, then Report junk. The message moves to Junk Email and is submitted to Microsoft's spam intelligence system. Reporting does not automatically add the sender to your blocked list.

What an admin can configure in Microsoft Defender#

The controls below require the Security Administrator or Organization Management role in Microsoft 365. If junk mail is reaching multiple users, bypassing personal filters, or arriving from a domain that should never reach anyone in the organization, these are your tenant-level tools.

  1. 1

    Add blocked senders or domains to the anti-spam policy

    In the Microsoft Defender portal at security.microsoft.com, go to Email and collaboration, then Policies and rules, then Threat policies, then Anti-spam. Select the default inbound policy and edit the Allow and block list section. Add sender addresses or domain names to the Blocked senders or Blocked domains list. Mail matching these entries is treated as spam and moved to the recipient's Junk Email folder — not quarantined. Subdomains are automatically included: blocking contoso.com also blocks mail.contoso.com without any extra entries.

  2. 2

    Block a domain in the Tenant Allow/Block List

    In the Microsoft Defender portal, go to Email and collaboration, then Policies and rules, then Tenant Allow/Block Lists. On the Domains and addresses tab, select Add, then Block. Enter one address or domain per line. To block a domain and all its subdomains, use the wildcard syntax *.domain.com — for example, *.contoso.com. Entering only contoso.com blocks that exact domain but does not cover subdomains; mail from mail.contoso.com or newsletters.contoso.com will still get through. Mail matching a TABL block entry is classified as high-confidence phishing and moved to quarantine, not the Junk Email folder. Recipients cannot release high-confidence phishing from quarantine on their own — an admin must approve it.

  3. 3

    Review quarantined mail

    Quarantined mail is visible at security.microsoft.com/quarantine. Admins can review, release, or permanently delete messages there. Quarantine notifications, if configured in quarantine policies, alert recipients when mail is being held. For high-confidence phishing verdicts, recipients can request release, but an admin must approve the request before the message is delivered.

  4. 4

    Check for conflicting allow entries

    If a sender keeps reaching inboxes despite a block, open the Tenant Allow/Block List and look for an allow entry covering the same domain or address. Allow entries submitted via the Submissions page at security.microsoft.com/reportsubmission can override spam filtering for the verdicts they cover. Remove any allow entry that is no longer needed, or shorten its expiry. Within the TABL, block entries take precedence over allow entries.

Anti-spam policy vs Tenant Allow/Block List: choosing the right tool#

The right choice depends on what outcome you need. Mail from an anti-spam policy blocked domain lands in the recipient's Junk Email folder, where they can still retrieve it. Mail from a TABL-blocked domain or address goes to quarantine as high-confidence phishing and requires admin action to release.

Junk folder vs quarantine: a real operational difference

Add a domain to the anti-spam policy blocked domains list when you want mail delivered to Junk — users can still check it themselves. Add it to the Tenant Allow/Block List when you want it held in quarantine without user access. Use the TABL for persistent threats; use the anti-spam blocked list for bulk or commercial mail that users may legitimately need to retrieve.

User vs admin: what each control does#

ControlWho sets itScopeBlocked mail lands inSubdomains covered
Blocked Senders list in OutlookUserYour mailbox onlyJunk Email folderOnly if added separately
Anti-spam policy blocked domainsAdminAll recipients, tenant-wideJunk Email folderYes, automatically
Tenant Allow/Block List — domain blockAdminAll recipients, tenant-wideQuarantine (high-confidence phishing)Only with *.domain.com syntax
Tenant Allow/Block List — address blockAdminAll recipients, tenant-wideQuarantine (high-confidence phishing)N/A
Safe Senders list in OutlookUserYour mailbox onlyInbox (bypasses Junk filter)N/A

Why a blocked sender still arrives#

The most common cause is a tenant-level allow entry upstream. When an admin adds a domain to the Tenant Allow/Block List as an allow entry — even temporarily, as can happen during false-positive remediation — Exchange Online Protection clears that sender before mail reaches your mailbox. Your Junk Email filter runs after EOP delivery, so mail that EOP has already cleared bypasses your personal blocked-senders list entirely.

A second cause: bulk senders rotate sending addresses inside one domain. If you blocked a specific address but not the domain, new addresses from the same sender continue to arrive. The fix is to block the domain, not just the address.

A third cause applies specifically to admins. A TABL block on spamsource.com without the wildcard prefix does not stop mail from mail.spamsource.com or any other subdomain. The anti-spam policy blocked domains list handles subdomains automatically; the Tenant Allow/Block List does not. Admins who set a domain block in the TABL and still see subdomain mail getting through need to re-enter the entry using the *.spamsource.com format.

Two-stage Microsoft 365 mail filtering diagram showing the tenant-level EOP layer running first (anti-spam policy and Tenant Allow/Block List), followed by the per-mailbox Junk Email filter in Outlook after delivery
EOP runs before delivery; your Outlook Junk Email filter runs after. A tenant-level TABL allow entry clears a message at the first stage, before your personal blocked-senders list has any chance to act.

A faster way to stay ahead of junk#

The steps above handle senders you already know about. The harder problem is mail that has not triggered a block yet: cold outreach on fresh domains, phishing attempts rotating past a blocked address, or newsletters that cleared spam filters because you once opted in.

AI Emaily's spam protection and cold-email filter work at the mail-client layer, matching on sender behavior and domain patterns rather than individual addresses. When a bulk sender rotates addresses inside the same domain, the filter catches the rotation rather than waiting for you to set another manual block. The rules brain lets you file, label, or archive mail consistently across every connected account — including Microsoft 365 mailboxes.

We build AI Emaily. It works alongside Microsoft Defender's tenant policies, not instead of them: Defender governs your organization's perimeter; AI Emaily handles triage and filing once mail lands in your inbox.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Stop managing junk email manually

AI Emaily filters and files your inbox across every account — including Microsoft 365.

  • 7-day free trial
  • Cancel anytime
  • Every provider