Blocking a domain also stops your own people emailing it. Most teams find that out from a bounce message.
Block entries for domains and email addresses prevent users in your organisation from sending to them, and the entire message is blocked for every recipient even if only one address matches. The Tenant Allow/Block List is powerful, and it behaves in ways that are worth knowing first.

- 5 minutesBefore a new entry starts working
- 30 daysDefault block entry expiry, up to 90 or never
- 45 daysHow long submission allow entries are kept
- Blocks winBlock entries take precedence over allows
Eight behaviours that determine whether this helps or hurts.
Blocks take precedence over allows
Stated directly, and it resolves most confusion about why an allowed sender is still being quarantined. If a message contains a URL or domain that is blocked, it can be classified as high confidence phishing and quarantined even when the sender is legitimate.
A domain block stops outbound mail too
Block entries for domains and email addresses also prevent your users from sending to them. The bounce is explicit, a 550 5.7.703 non-delivery report naming the Tenant Allow Block List, and the entire message is blocked for all recipients even if only one address matched.
It matches the From address, not the envelope sender
Entries apply to the From address, the 5322.From or P2 sender, rather than the MAIL FROM address, the 5321.MailFrom or envelope sender. That distinction matters when you are blocking something that forges one and not the other, and it is a common source of entries that do not work.
Blocking makes something high confidence phishing
Blocking a sender or domain here treats those messages as high confidence phishing, which carries the strictest quarantine handling. If you want them treated as spam instead, the blocked senders or blocked domains list in anti-spam policies is the right place, not this one.
Expiry, which differs by entry type
Blocks on domains and addresses, files and URLs expire after 30 days by default and can be set up to 90 days or to never expire. Blocks on spoofed senders, IP addresses and Teams domains never expire at all, which means they accumulate unless somebody reviews them.
Allows you cannot create directly
For malware and high confidence phishing verdicts you cannot create an allow entry here. You submit through the Submissions page and confirm the item is clean, and the allow entry is created from that. Files cannot be allowed directly at all, only through submission.
Allows expire, and are removed when unnecessary
Allow entries for domains and addresses, files and URLs are kept for 45 days after the filtering system determines the entity is clean, then removed. You can also set them to expire up to 30 days after creation. Spoofed sender allow entries never expire.
Microsoft cleans up after you, and tells you
If Microsoft determines an allow entry is no longer needed, the entry is automatically removed and the built-in threat management alert policy named Removed an entry in Tenant Allow/Block List creates an alert. That alert is worth routing somewhere, because it is genuinely useful.
One blocked recipient blocks the whole message, for everyone on it.
This is the outbound half of a block entry, and it is the part almost nobody expects when they block a domain for inbound reasons.
- Block entries for domains and email addresses prevent users in the organisation from sending email to those blocked domains and addresses. Senders receive a non-delivery report reading 550 5.7.703, naming the Tenant Allow Block List as the cause, which at least makes it diagnosable.
- The scope is wider than the match. Microsoft states the entire message is blocked for all internal and external recipients, even if only one recipient email address or domain is defined in a block entry. So one blocked address on a distribution of twenty stops the message reaching any of them.
- The related point is severity. Blocking a sender or domain in this list treats those messages as high confidence phishing, which is the strictest handling in the product. If the intent was simply to reduce nuisance mail, the blocked senders and blocked domains lists in anti-spam policies express that far better.
- IP and Teams blocks are more absolute again. A manual IP block drops all incoming mail from that address at the edge of the service. A Teams block blocks incoming communication from that domain and address and deletes existing communication. Neither expires by default.
Four principles for a list that stays useful.
We prefer submissions to manual allow entries
Submitting a false positive and confirming it is clean creates the allow entry as a consequence of a Microsoft judgement, and it also improves the filter for everyone. A manual allow entry only weakens your own filtering. Where both routes exist, the submission route is better in both directions.
We check the outbound consequence of every domain block
Users cannot send to a blocked domain, and the entire message fails for every recipient even if one address matched. A domain blocked during an incident three years ago can quietly break communication with a company you now supply, and the only symptom is a bounce nobody escalates.
We give special attention to entries that never expire
Blocks on spoofed senders, IP addresses and Teams domains never expire, and IP blocks drop mail at the edge of the service while Teams blocks delete existing communication. Those are the entries most likely to be both forgotten and consequential, so they get reviewed first.
We match severity to intent
Blocking here treats messages as high confidence phishing. Where the actual intent was to stop nuisance mail, the blocked senders and blocked domains lists in anti-spam policies are the right instrument. Using the strictest control for a mild problem creates quarantine handling nobody wanted.
Four phases across roughly three weeks.
- 01Week 1
Export and attribute every entry
All six entry types, with what each was for, who added it and when. Entries that never expire, meaning spoofed senders, IP addresses and Teams domains, get particular attention because they persist indefinitely without anybody deciding they should.
- Full export across all entry types
- Never-expiring entries identified
- Attribution attempted per entry
- Entries with no owner or reason listed
- 02Week 2
Assess the allow entries as risk
Unnecessary allow entries expose the organisation to mail the system would otherwise filter, so each one needs justification. Allows created through submissions are less concerning because they exist as a result of a Microsoft judgement, and they age out.
- Each allow entry justified or removed
- Submission-created allows distinguished from manual ones
- Expiry set where entries were left permanent
- Attack simulation URLs moved to advanced delivery policy
- 03Week 2 to 3
Assess the block entries for collateral
The outbound consequence checked for every domain block, since users cannot send to a blocked domain and the whole message fails for every recipient. Severity checked too, because blocking here means high confidence phishing rather than spam.
- Outbound impact assessed per domain block
- Blocks better expressed as anti-spam entries identified
- Never-expiring blocks reviewed and dated
- IP and Teams blocks confirmed as still intended
- 04Week 3
Set the operating process
A route for adding entries that captures reason and owner, a preference for submissions over manual allows, and the Removed an entry in Tenant Allow/Block List alert routed to somebody. Otherwise the list starts accumulating again immediately.
- Entry request and approval process defined
- Submissions preferred over manual allow entries
- Removal alert routed to a named owner
- Recurring review scheduled
Six situations where this list is the cause or the cure.
A business that cannot email a customer
The bounce says 550 5.7.703 and names the Tenant Allow Block List, which is at least diagnosable once somebody reads it. The cause is almost always a domain blocked during an old incident, and the fix is a minute once the connection is made.
An organisation whose allowed sender keeps getting quarantined
Block entries take precedence over allow entries, so a URL or domain blocked somewhere in the list overrides the sender allow. Microsoft advises reviewing block entries for URLs or domains in the affected messages, which is exactly the right first step.
A regulated firm auditing its filtering exceptions
Every allow entry is a documented weakening of a control, and an auditor asking why one exists is a reasonable question. Being able to answer per entry, with a reason and an owner, is the difference between a clean finding and an uncomfortable conversation.
An operator running phishing simulations
Microsoft is explicit that URL allow entries should not be used for phishing URLs from non-Microsoft attack simulation training, and that the advanced delivery policy is the right place instead. Simulation URLs sitting in the allow list are a genuine exposure rather than a tidiness issue.
A company that inherited a tenant
After an acquisition or a change of provider, the list arrives with entries nobody can explain, some of which never expire. Attribution and review is one of the higher-value early tasks, because IP blocks and Teams blocks in particular have effects that persist silently.
A business submitting the same false positive repeatedly
For URLs this is usually unnecessary. Reporting one URL covers its variations, so reporting www.contoso.com/abc also covers the same path with query strings and additional segments. Knowing that removes a recurring task that several people were quietly doing.
How UAE organisations manage manual overrides.
| Feature | Managed with a process | Reviewed occasionally | Accumulated over years |
|---|---|---|---|
Every entry has a reason recorded | Yes | Some | No |
Allow entries justified | Individually | Rarely | No |
Submissions preferred over manual allows | Yes | Sometimes | No |
Never-expiring entries reviewed | On a schedule | No | No |
Outbound impact of blocks understood | Yes | Partly | Discovered via NDR |
Severity chosen deliberately | Phishing or spam as intended | Default | Default |
Attack simulation URLs handled correctly | Advanced delivery policy | Sometimes here | Here |
Removal alerts monitored | Yes | No | No |
List size trending | Stable | Growing | Growing |
Risk from stale allows | Low | Moderate | Unknown |
Ten differences worth knowing before you add an entry.
| Entry type | Block behaviour | Block expiry | |
|---|---|---|---|
| Domains and email addresses | Treated as high confidence phishing, quarantined | 30 days default, up to 90 or never | |
| Files | Blocked as malware, quarantined | 30 days default, up to 90 or never | |
| URLs | Blocked as high confidence phishing, quarantined | 30 days default, up to 90 or never | |
| Spoofed senders | Manual override of a spoof intelligence allow | Never expires | |
| IP addresses | All incoming mail dropped at the service edge | Never expires | |
| Teams domains and addresses | Communication blocked and existing communication deleted | Never expires | |
| Allow, domains and addresses | Direct creation only for bulk, spam and phishing | Kept 45 days after judged clean | |
| Allow, URLs | Direct creation only for the same verdicts | Kept 45 days after judged clean | |
| Allow, files | Cannot be created directly, submission only | Kept 45 days after judged clean | |
| Allow, spoofed senders | Can be created proactively | Never expires |
Five steps, and most of the value is in the first two.
- 1
Export every entry type and attribute what you can
Domains and email addresses, files, URLs, spoofed senders, IP addresses and Teams domains. Each with a date, an author where the record exists, and a reason. Entries nobody can explain are recorded as such rather than removed immediately.
- 2
Assess allow entries individually
Unnecessary allow entries expose the organisation to mail the system would otherwise filter. Manual allows get the closest scrutiny, submission-created allows less so since they follow a Microsoft clean judgement and age out after 45 days.
- 3
Assess block entries for outbound and severity impact
Every domain block checked for whether the organisation now needs to email that domain, since outbound is blocked and the whole message fails. Severity checked too, because a block here means high confidence phishing rather than spam.
- 4
Fix the misplaced entries
Attack simulation URLs moved to the advanced delivery policy, nuisance senders moved to anti-spam blocked lists where phishing severity was never intended, and expiry set on entries that were left permanent without a reason.
- 5
Put a process and an alert in place
A request route capturing reason and owner, submissions preferred over manual allows, the Removed an entry in Tenant Allow/Block List alert routed to somebody, and a recurring review so the list does not simply refill over the next two years.
What organisations ask about the Tenant Allow/Block List.
Fifteen questions about your own list.
Inventory
- How many entries exist in total?Across all six types.
- How many never expire?Spoof, IP and Teams entries do not.
- Can we say why each was added?Usually not.
- Who added them?And are they still here.
- Any IP blocks still in place?They drop mail at the edge.
Allows
- How many manual allow entries do we have?Each weakens the filter.
- Were they created by submission?Preferable to manual.
- Do any have no expiry?Set one where you can.
- Are attack simulation URLs in here?They belong in advanced delivery.
- Do we see the automatic removal alerts?Route them somewhere.
Blocks
- Do any block domains we now do business with?Outbound would fail.
- Should any of these be anti-spam entries instead?For spam rather than phishing severity.
- Have we tested sending to a blocked domain?The NDR is 550 5.7.703.
- Do we block on From or expect envelope matching?It is the From address.
- Are Teams blocks still appropriate?They delete existing communication.
Export your list and count how many entries you can actually explain.
Then check whether any blocked domain is one you now need to email, because outbound is blocked too and the bounce is easy to miss. Both checks take under an hour.
Related Services
Explore more solutions that work great with this service
Quarantine Policies
Who can see, act on and release blocked mail
Anti-Phishing Policies
Impersonation protection, spoof handling and thresholds
Email Security Audit
Authentication, policy, exceptions, routing, mailboxes
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Safe Links
Time-of-click URL checks in mail, Teams and Office
Attack Simulation Training
Phishing simulation you probably already own, including QR codes
Microsoft Defender
Advanced endpoint and email threat protection