How to block spam emails based on patterns in Exchange Online using Data loss prevention.

To create a spam email block policy based on patterns in Microsoft Exchange Online with DLP 365 you can follow the steps outlined below:

For instance, if you are receiving spam emails from various accounts, Blow example email Password expiration reminder. Normally we don’t receiving emails like that.


.

In Exchange online before we create these rules in Exchange online now it moved to DLP (Data loss prevention) under https://compliance.microsoft.com/datalossprevention

To create policy please follow following steps.

1.       Login to https://compliance.microsoft.com/datalossprevention

2.       go under DLP and Create Policy



3.       Select: Categories: Custom, Template Custom policy, Click Next



4.       Provide the name and description and Click Next



5.       Skip Admin units if you can see this option.

6.       Choose location to apply the policy.

a.       Note: you can choose all location but our policy for incoming emails to we will choose Exchange only. Click Next



7.       Define Policy Settings Choose: Create or customize advance DLP rules and Click Next

8.       Customize advanced DLP rules: Click Create Rule

a.       Provide All required information.

b.       In conditions select Recipient domain is (Your Domain) and

c.       In conditions select Subject matches patterns condition

                                                               i.      Put all the patterns from spam email subject line.

d.       In Conditions you also can choose Subject or Body matches patterns

Note: you can use condition AND or OR between two policies if you want both the policies to must apply select AND or if you want any of the policy to apply select OR

Note: In our case we creating policy for incoming email that’s why we have recipient domain and our policy based on subject matches patterns.



e.       Actions: you can select request action to block in quarantine or forward the message



f.        Click Save

g.       You can also apply settings to send alerts (Use this severity level in admin alerts and reports:)

9.       Click Next



10Policy mode: you can test before Turn it on: Click Next



11Review and Click Submit

12To test the effectiveness of the policy, you can send an email to your M365 email address using the same patterns. As a result, all such emails will be blocked and sent to quarantine.

You can access the Quarantine section by navigating to security.microsoft.com > Email & Collaboration > Review > Quarantine.

 


 

 

Comments

Popular posts from this blog

How to check when Sharepoint List was created using PowerShell.

How to connect SharePoint online with SharePoint designer 2013

How to Send email from Scanner or Custom Applications using Microsoft365 SMTP or MX record