Maximize your protection, eliminate business risks.
Optimize and modernize with cloud transformation.
Empower your people to work securely from anywhere.
Let us handle IT so you can focus on growing your business.
Get multichannel 24/7/365 expert end-user support.
Protect, detect, and respond—Dataprise keeps your business secure.
Maximize uptime with with industry-leading DRaaS.
Swiftly mitigate cyber threats and restore security.
Improve efficiency, productivity and outcomes with cloud.
Ensure all mobile devices, everywhere, are secure.
Gain a competitive edge with strategic IT solutions.
This battle-tested checklist enables your team to swiftly initiate a ransomware response.
IT for businesses of all sizes, in any industry.
Empower institution growth with custom IT solutions.
Ensure your firm is always in compliance.
Improve patient care and staff morale.
Deal with pressing legal matters, not IT.
Keep up with the evolving digital landscape.
Focus on your mission by outsourcing IT.
Accelerate PE client deals and secure data.
Empower Your Municipality with Secure, Reliable IT Services
Execute initiatives and develop IT strategies.
Get the latest industry insights and trends.
Join us at events in person and online.
Hear from clients and learn more about strategic IT.
See how Dataprise can make IT your greatest asset.
Get informative technical resources from IT experts.
Stay on stop of emerging cybersecurity threats.
Discover the key areas of DR your organization needs to address to ensure downtime is minimized.
Gain a strategic asset by bringing harmony to IT.
Ensure 24/7 support and security with dedicated teams.
Drive business forward by partnering with Dataprise.
Meet our one-of-a-kind leadership team.
Discover the recognition Dataprise has earned.
Help us help businesses with strategic IT.
Grow through acquisition and partnership with Dataprise.
Embracing different perspectives and backgrounds.
Find a Dataprise location near you.
Dataprise is committed to empowering more women to consider a career in technology.
Explore our trusted partnerships with leading tech innovators.
Posts
By: Dataprise
Table of content
Sometimes Exchange can be a little overzealous in protecting you from spam and other unwanted email. To make sure messages get through, you can whitelist email addresses in Microsoft 365.
We get this question a lot from IT Pros and people just getting started in the Microsoft 365 Admin center. If you’re not an Office 365 admin, you can use our end-user instructions for whitelisting email addresses from Outlook, here.
[image_with_animation image_url=”29767″ image_size=”medium” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”100%” max_width_mobile=”default” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″]
[image_with_animation image_url=”29769″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”default” max_width=”100%” max_width_mobile=”default” margin_top=”15″ margin_bottom=”15″]
[image_with_animation image_url=”29771″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”default” max_width=”custom” margin_top=”15″ margin_bottom=”15″ max_width_custom=”350px”]
[image_with_animation image_url=”29772″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”default” max_width=”custom” margin_top=”15″ margin_bottom=”15″ max_width_custom=”350px”]
Once you save the policy, it may take up to an hour for the changes to take effect. After that, the emails from the whitelisted senders or domains will be delivered to your inbox without being scanned or filtered by Defender.
Creating an allow policy in the Microsoft Defender admin center can help you avoid missing important or trusted emails that may otherwise be blocked or filtered by the default security settings. However, whitelisting also comes with some risks, as it bypasses the protection mechanisms that Defender provides against spam, phishing, malware, and other threats. Therefore, you should carefully weigh the pros and cons of whitelisting an email address or domain, and only do so if you are confident that the sender or domain is trustworthy and reliable. Whitelisting should not be used as a substitute for good email hygiene and security awareness, but rather as a complementary tool to enhance your communication and collaboration.
For specific domains or IP addresses, Microsoft prefers whitelisting to be done from the Defender or Security Admin centers as detailed in the instructions above. If you’re facing a problem where mail is still being marked as spam, you can use mail flow rules in the Exchange Admin Center to bypass spam filtering and fix this problem. One situation where this is common is if you have mail coming from an on-premises Exchange going to Exchange Online. Here are the steps you’ll need to take to bypass such spam filtering:
Keep in mind that whitelisting domains in Microsoft 365 can leave your organization vulnerable to threats from accounts that spoof the allowed domain. To mitigate some of this risk, we recommend adding an additional condition that checks if the message was sent from the domain’s registered servers:
[image_with_animation image_url=”25442″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”350px”]
[image_with_animation image_url=”25443″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”350px”]
[image_with_animation image_url=”25444″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”100%” max_width_mobile=”default” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″]
Whitelisting a single email address is the safest course of action, since whitelisting an entire email domain allows malicious actors to spoof any address on the allowed domain to deliver spam and phishing messages directly to user inboxes.
[image_with_animation image_url=”25445″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”350px”]
[image_with_animation image_url=”25446″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”500px”]
[image_with_animation image_url=”25447″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”350px”]
[image_with_animation image_url=”25448″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”600px”]*Whitelisting an entire domain can leave your organization vulnerable to threats from accounts that spoof the allowed domain. To mitigate some of this risk, we recommend adding an additional condition that checks if the message was sent from the domain’s registered servers:
[image_with_animation image_url=”25449″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”400px”]
[image_with_animation image_url=”25450″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”400px”]
[image_with_animation image_url=”25451″ image_size=”full” animation_type=”entrance” animation=”None” animation_movement_type=”transform_y” hover_animation=”none” constrain_group_1=”yes” constrain_group_3=”yes” constrain_group_5=”yes” alignment=”” border_radius=”none” box_shadow=”none” image_loading=”lazy-load” max_width=”custom” margin_top=”15″ margin_bottom=”15″ margin_top_tablet=”10″ margin_bottom_tablet=”10″ margin_top_phone=”10″ margin_bottom_phone=”10″ max_width_custom=”600px”]That’s it! Now you have an Office 365 domain whitelist, and emails from that address will be delivered to your organization’s inboxes, not marked as junk.
INSIGHTS
Subscribe to our blog to learn about the latest IT trends and technology best practices.