Outbound Wiki

Article

defender-docs/defender-office-365/outbound-spam-policies ...

github.com

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. Use PowerShell to set the priority of outbound spam filter rules Changing the priority of an existing rule can have a cascading effect on other rules. To set the priority of an outbound spam filter rule in PowerShell, use the following syntax:

    In Branch precedence and conflict handling

  2. On the Name your policy page, configure these settings: Name: Enter a unique, descriptive name for the policy. Description: Enter an optional description for the policy. When you're finished on the Name your policy page, select Next. Domains: All senders in the organization with a primary email address in the specified accepted domain. For example, you configure a condition with the following values: Users: [email protected] Groups: Executives The policy is applied to [email protected] only if he's also a member of the Executives group. Otherwise, the policy isn't applied to him. Exclude these users, groups, and domains: To add exceptions for the internal senders that the policy applies to, select this option and configure the exceptions (sender exceptions). You can use an exception only once, but the exception can contain multiple values: Multiple values of the same exception use OR logic (for example, <sender1> or <sender2>). If the recipient matches any of the specified values, the policy isn't applied to them. Different types of exceptions use OR logic (for example, <sender1> or <member of group1> or <sender domain1>). If the recipient matches any of the specified exception values, the policy isn't applied to them. When you're finished on the Users, groups, and domains page, select Next.

    In Domain and mailbox architecture

  3. For example, you configure a condition with the following values: Users: [email protected] Groups: Executives The policy is applied to [email protected] only if he's also a member of the Executives group. Otherwise, the policy isn't applied to him. Exclude these users, groups, and domains: To add exceptions for the internal senders that the policy applies to, select this option and configure the exceptions (sender exceptions). You can use an exception only once, but the exception can contain multiple values: Multiple values of the same exception use OR logic (for example, <sender1> or <sender2>). If the recipient matches any of the specified values, the policy isn't applied to them. Different types of exceptions use OR logic (for example, <sender1> or <member of group1> or <sender domain1>). If the recipient matches any of the specified exception values, the policy isn't applied to them. When you're finished on the Users, groups, and domains page, select Next. Set an external message limit: The maximum number of external recipients per hour. For instructions, see Remove blocked users from the Restricted entities page. No action, alert only: The alert policy named Email sending limit exceeded notifies admins (via email and on the Incidents & alerts > View alerts page). Forwarding rules section: The setting in this section controls automatic email forwarding by Exchange Online mailboxes to external recipients. For more information, see Control automatic external email forwarding. Select one of the following actions from the Automatic forwarding rules dropdown list: Automatic - System-controlled: This value is the default. When this value was introduced, it was equivalent to On - Forwarding is enabled. In 2021, the value changed to Off - Forwarding is disabled for new organizations and for existing organizations that weren't actively using the Automatic - System-controlled value. For existing organizations that were already using the value, it can remain equivalent to On - Forwarding is enabled. Because the behavior can differ by organization, configure On - Forwarding is enabled or Off - Forwarding is disabled instead of Automatic - System-controlled. For more information, see All you need to know about automatic email forwarding in Exchange Online. On - Forwarding is enabled: Automatic external email forwarding isn't disabled by the policy. Off - Forwarding is disabled: All automatic external email forwarding is disabled by the policy. [!NOTE] Disabling automatic forwarding disables any Inbox rules or mailbox forwarding (also known as SMTP forwarding) that redirects messages to external addresses. Outbound spam policies don't affect the forwarding of messages between internal users. When automatic forwarding is disabled by an outbound spam policy, non-delivery reports (also known as NDRs or bounce messages) are generated in the following scenarios: Messages from external senders for all forwarding methods. Messages from internal senders if the forwarding method is mailbox forwarding.

    In Mailbox sending capacity

  4. For example, you configure a condition with the following values: Users: [email protected] Groups: Executives The policy is applied to [email protected] only if he's also a member of the Executives group. Otherwise, the policy isn't applied to him. Exclude these users, groups, and domains: To add exceptions for the internal senders that the policy applies to, select this option and configure the exceptions (sender exceptions). You can use an exception only once, but the exception can contain multiple values: Multiple values of the same exception use OR logic (for example, <sender1> or <sender2>). If the recipient matches any of the specified values, the policy isn't applied to them. Different types of exceptions use OR logic (for example, <sender1> or <member of group1> or <sender domain1>). If the recipient matches any of the specified exception values, the policy isn't applied to them. When you're finished on the Users, groups, and domains page, select Next. Set an internal message limit: The maximum number of internal recipients per hour. For instructions, see Remove blocked users from the Restricted entities page. No action, alert only: The alert policy named Email sending limit exceeded notifies admins (via email and on the Incidents & alerts > View alerts page). Forwarding rules section: The setting in this section controls automatic email forwarding by Exchange Online mailboxes to external recipients. For more information, see Control automatic external email forwarding. Select one of the following actions from the Automatic forwarding rules dropdown list: Automatic - System-controlled: This value is the default. When this value was introduced, it was equivalent to On - Forwarding is enabled. In 2021, the value changed to Off - Forwarding is disabled for new organizations and for existing organizations that weren't actively using the Automatic - System-controlled value. For existing organizations that were already using the value, it can remain equivalent to On - Forwarding is enabled. Because the behavior can differ by organization, configure On - Forwarding is enabled or Off - Forwarding is disabled instead of Automatic - System-controlled. For more information, see All you need to know about automatic email forwarding in Exchange Online. On - Forwarding is enabled: Automatic external email forwarding isn't disabled by the policy. Off - Forwarding is disabled: All automatic external email forwarding is disabled by the policy. [!NOTE] Disabling automatic forwarding disables any Inbox rules or mailbox forwarding (also known as SMTP forwarding) that redirects messages to external addresses. Outbound spam policies don't affect the forwarding of messages between internal users. When automatic forwarding is disabled by an outbound spam policy, non-delivery reports (also known as NDRs or bounce messages) are generated in the following scenarios: Messages from external senders for all forwarding methods. Messages from internal senders if the forwarding method is mailbox forwarding.

    In Mailbox sending capacity

  5. For example, you configure a condition with the following values: Users: [email protected] Groups: Executives The policy is applied to [email protected] only if he's also a member of the Executives group. Otherwise, the policy isn't applied to him. Exclude these users, groups, and domains: To add exceptions for the internal senders that the policy applies to, select this option and configure the exceptions (sender exceptions). You can use an exception only once, but the exception can contain multiple values: Multiple values of the same exception use OR logic (for example, <sender1> or <sender2>). If the recipient matches any of the specified values, the policy isn't applied to them. Different types of exceptions use OR logic (for example, <sender1> or <member of group1> or <sender domain1>). If the recipient matches any of the specified exception values, the policy isn't applied to them. When you're finished on the Users, groups, and domains page, select Next. Set a daily message limit: The maximum total number of recipients per day. For instructions, see Remove blocked users from the Restricted entities page. No action, alert only: The alert policy named Email sending limit exceeded notifies admins (via email and on the Incidents & alerts > View alerts page). Forwarding rules section: The setting in this section controls automatic email forwarding by Exchange Online mailboxes to external recipients. For more information, see Control automatic external email forwarding. Select one of the following actions from the Automatic forwarding rules dropdown list: Automatic - System-controlled: This value is the default. When this value was introduced, it was equivalent to On - Forwarding is enabled. In 2021, the value changed to Off - Forwarding is disabled for new organizations and for existing organizations that weren't actively using the Automatic - System-controlled value. For existing organizations that were already using the value, it can remain equivalent to On - Forwarding is enabled. Because the behavior can differ by organization, configure On - Forwarding is enabled or Off - Forwarding is disabled instead of Automatic - System-controlled. For more information, see All you need to know about automatic email forwarding in Exchange Online. On - Forwarding is enabled: Automatic external email forwarding isn't disabled by the policy. Off - Forwarding is disabled: All automatic external email forwarding is disabled by the policy. [!NOTE] Disabling automatic forwarding disables any Inbox rules or mailbox forwarding (also known as SMTP forwarding) that redirects messages to external addresses. Outbound spam policies don't affect the forwarding of messages between internal users. When automatic forwarding is disabled by an outbound spam policy, non-delivery reports (also known as NDRs or bounce messages) are generated in the following scenarios: Messages from external senders for all forwarding methods. Messages from internal senders if the forwarding method is mailbox forwarding.

    In Mailbox sending capacity

  6. The recipient rate limits are restricted to smaller values than the defaults. For more information, see Sending limits across Microsoft 365 options. After one of the limits is reached, the user is prevented from sending messages. For detailed syntax and parameter information, see New-HostedOutboundSpamFilterPolicy.

    In Mailbox sending capacity