How to Whitelist a Domain in Office 365 (2024)

Sometimes legitimate email ends up in the junk folder after being marked as spam by Exchange Online. This is of course unwanted, so how do you whitelist a domain in Office 365? And how can we do it safely without opening the doors for phishing emails?

Filtering out spam emails is important to prevent malware and phishing emails from ending up in your user’s mailboxes. But when emails from trusted senders are marked as spam we need to find a way to override this and safely deliver the mail into the user’s inbox.

In this article, we are going to take a look at the different options to whitelist a domain in Office 365.

What you need to know

There are multiple ways to whitelist a domain in Office 365, but it’s important that you understand the implications of the different methods. There are various reasons why an email is marked as spam. It can be that it’s sent from an untrusted source, failed the SPF or DMARC check, or even based on the content of the email.

The two most common ways to whitelist a domain on a tenant level are by either using a mail flow rule (recommended) or by adding the domain to the allowed sender list in the anti-spam policy. Other options are to whitelist on IP Address in Office 365 or use the safe sender list in Outlook.

When it comes to excluding a domain from spam filtering, it’s important to be as specific as possible about the source. Because when filtering simply on a domain name alone, you also set the door open for spoofed phishing emails for that domain.

That is why mail flow rules are the recommended way to whitelist a domain.

Whitelist a Domain in Office 365 with Mail flow rules

We are going to start with the recommended method, with mail flow rules. The advantage of mail flow rules is that we can whitelist a domain and also add some additional checks to it. Like part of the subject, DMARC result, or even a specific IP Address.

When you have a web application, for example, that sends an automatically generated email that you want to whitelist, then you can create a mail flow rule, and filter on the sender or domain. As an extra check, you can add another filter on the IP Address, because you probably know from which IP Address the mail is sent.

To whitelist a domain with a mail flow rule we first need to open the Exchange Admin Center.

  1. Expand Mail flow and click on Rules
  2. Click on the Plus icon to create a new rule
How to Whitelist a Domain in Office 365 (1)
  1. Enter a name for the rule
  2. Under Apply this rule if, select The Sender > Domain is
  3. Enter the domain that you want to whitelist
  4. Click on the Plus icon to add a condition
  5. Select The Sender > IP Range is any of these
  6. Enter the IP Address of the application.
How to Whitelist a Domain in Office 365 (2)
  1. Under Do the following, select Modify the message properties > Set the Spam confidence level
  2. Select Bypass spam filtering (-1)
  3. Click on the Plus icon to add an action
  4. Choose Modify the message properties > Set a message header
  5. Set the header to X-ETR and the value to something like: Bypass spam filtering for stonegrovebank.com

Other additional conditions that you can use are:

  • The Subject or Body > Subject includes any of these words. This way you can further filter the emails based on a word in the subject line.
  • A Message header > includes any of these words. Filter on DMARC result is a good way to prevent spoofing of a whitelisted domain. Add Authentication-Results under “Enter text” and dmarc=passunder “Enter words…”

Click Next when done.

In the Set Rule Settings, you can set the rule in Test mode first if you want. Otherwise, set the severity to Not Audit and click on Next and Finish

Office 365 Whitelist Domain with Allowed Domains

Before we could use the allowed sender list in the Exchange Online admin center to whitelist a domain. But now we need to use the Microsoft 365 Security Center (Microsoft 365 Defender). Keep in mind that this is the least secure option to whitelist a domain. Because this way senders for this domain will bypass spam protection and sender authentication methods.

To allow a complete domain or specific sender, we need to modify the inbound spam policy.

  1. Click on Policies & Rules
  2. Select Threat Policies
  3. Open Anti-Spam (it can take a couple of seconds to load the policies)
  4. Click on the Anti-spam inbound policy (Default)
How to Whitelist a Domain in Office 365 (3)
  1. Scroll all the way down in the fly-out and click on Edit allowed and blocked senders and domains
How to Whitelist a Domain in Office 365 (4)
  1. Click on Allow domains
  2. Add the domains that you want to whitelist
  3. Click Done and Save

Mails sent from this domain should now arrive in the inbox and completely bypass the spam filter. But keep in mind, when you whitelist a domain this way, that spoofed email won’t be noticed as well.

Office 365 Whitelist IP Address

The last option that I want to share with you is the ability to whitelist an IP Address in Office 365. Personally, I prefer to use a mail flow rule for this, which allows us to combine an IP Address with a domain for example. But we can whitelist an IP address completely as well.

For this, we need to modify the Connection Filter Policy in the security center (Microsoft 365 Defender).

  1. Open the Security Center (Microsoft 365 Defender)
  2. Navigate to Policies and Rules > Threat Rules
  3. Click on Anti-Spam
  4. Click on Connection Filter Policy (Default)
  5. Click Edit connection filter policy in the fly-out
  6. Add the IP Address that you want to whitelist
  7. Enable Turn on safe list
  8. Click Save and Close to apply the settings.
How to Whitelist a Domain in Office 365 (5)

Wrapping Up

Try always to be as specific as possible when whitelisting a domain in Office 365. If you know that a part of the subject is always the same, make sure you add it as a condition. Enable the DMARC header to check if SPF and DMARC are configured for the sending domain.

Whitelisting a domain through the allowed domains list in the anti-spam policy should only be used as a temporary solution. When you whitelist a domain that way, you bypass all the security checks that will help with preventing phishing mails.

If you have any questions, just drop a comment below.

How to Whitelist a Domain in Office 365 (2024)
Top Articles
Ester Bron Leaks
Thaliamatos Only Fans
LOST JEEPS • View forum
12 Rue Gotlib 21St Arrondissem*nt
Krua Thai In Ravenna
Smoothie Operator Ruff Ruffman
Morgandavis_24
Ms Ortencia Alcantara Instagram
They Cloned Tyrone Showtimes Near Showbiz Cinemas - Kingwood
Badddae
Low-iron glass : making a clear difference
Triple the Potatoes: A Farmer's Guide to Bountiful Harvests
8 Internet Celebrities who fell prey to Leaked Video Scandals
Jordanbush Only Fans
Six Broadway Wiki
Swgoh Boba Fett Counter
Amanda Balionis makes announcement as Erica Stoll strides fairways with Rory McIlroy
Best 2 Player Tycoons To Play With Friends in Roblox
Stolen Touches Neva Altaj Read Online Free
Dtm Urban Dictionary
Interview With Marc Rheinard (Team ToniSport & Awesomatix) From Germany
Sophia Garapetian Twitter
How a 1928 Pact Actually Tried to Outlaw War
Friend Offers To Pay For Friend’s B-Day Dinner, Refuses When They See Where He Chose
Offres Emploi Purchasing manager Paris (75000) | HelloWork
Smile 2022 Showtimes Near Savoy 16
Dead By Daylight Subreddit
Ohio Road Construction Map
Gestalt psychology | Definition, Founder, Principles, & Examples
R Toronto Blue Jays
Tamiblasters.in
Sun Commercial Obituaries
Worldfree4U In
Oldgamesshelf
Tamara Lapman
Switchback Travel | Best Camping Chairs of 2024
454 Cubic Inches To Litres
Xdefiant turn off crossplay ps5 cмотреть на RuClips.ru
Fisher-Cheney Funeral Home Obituaries
Mercantilism - Econlib
Unblocked Games 76 Bitlife
Santa Cruz Craigslist Cars And Trucks - By Owner
Nature's Medicine Uxbridge Menu
Makes A Successful Catch Maybe Crossword Clue
Papa Johns Pizza Hours
Adda Darts
Left Periprosthetic Femur Fracture Icd 10
Ttw Cut Content
Santa On Rakuten Commercial
Duxa.io Reviews
Munich Bavaria Germany 15 Day Weather Forecast
Only Partly Forgotten Wotlk
Latest Posts
Article information

Author: Rueben Jacobs

Last Updated:

Views: 6117

Rating: 4.7 / 5 (77 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Rueben Jacobs

Birthday: 1999-03-14

Address: 951 Caterina Walk, Schambergerside, CA 67667-0896

Phone: +6881806848632

Job: Internal Education Planner

Hobby: Candle making, Cabaret, Poi, Gambling, Rock climbing, Wood carving, Computer programming

Introduction: My name is Rueben Jacobs, I am a cooperative, beautiful, kind, comfortable, glamorous, open, magnificent person who loves writing and wants to share my knowledge and understanding with you.