Fix Exchange Dynamic Distribution Group Creation by Email Domain Error
Question details
The user is attempting to create an Exchange Online dynamic distribution group, but the filter fails when trying to match users whose email addresses end with a specific domain.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- An IT administrator wants to automatically group users by their specific email domain using Exchange Online filters.
- Observed behavior
- The dynamic distribution group filter fails because it utilizes a prefix wildcard, which is unsupported in Exchange Online due to performance limitations.
Verify that you have Exchange Administrator or Global Administrator privileges before attempting to modify dynamic distribution group rules or Entra ID settings.
Use Microsoft Entra ID Dynamic Membership Rules
Create a dynamic Microsoft 365 group in Microsoft Entra ID to successfully match users by their email domain.
Since Exchange Online dynamic distribution groups do not support prefix wildcards for performance reasons, Microsoft Entra ID is the recommended alternative. Entra ID dynamic groups support advanced queries, allowing you to accurately match domain suffixes.
Log in to the Microsoft Entra admin center with your administrator credentials.
Navigate to 'Groups', select 'All groups', and click on 'New group'.
Choose 'Microsoft 365' as the group type and set the 'Membership type' to 'Dynamic User'.
Click 'Add dynamic query' under the membership section. Construct a rule using syntax such as `(user.mail -match ".*@test.com")` to target the specific email domain.
Save the query and click 'Create'. Once populated, this group functions identically to an Exchange dynamic distribution group and supports email delivery.

Filter Using Supported Recipient Attributes
Use standard or custom Exchange attributes instead of domain wildcards to filter the distribution group.
Document Your IT Infrastructure with WPS Office
While Exchange configuration issues require Microsoft administrative tools, WPS Office is an excellent free, lightweight solution for documenting your IT policies, PowerShell scripts, and server rules.
- 1. Download and Install: Visit the official WPS Office website to download the free suite and install it on your workstation.
- 2. Draft IT Documentation: Launch WPS Writer to meticulously document your Exchange configurations, Entra ID membership queries, and administrative procedures.
- 3. Save and Share: Export your documents in standard Microsoft formats so your IT team can effortlessly view and collaborate on them.

Frequently Asked Questions
Why does using a wildcard like '*@test.com' fail in Exchange Online filters?
Exchange Online dynamic distribution groups do not support prefix wildcards (such as starting a string with an asterisk) due to significant performance constraints during recipient evaluation.
Are Microsoft Entra ID dynamic groups compatible with Exchange Online?
Yes. When you configure a Microsoft 365 dynamic group in Microsoft Entra ID, it becomes mail-enabled and functions perfectly as a distribution list within your Exchange Online environment.
Where should I seek assistance for complex Exchange PowerShell scripts?
For advanced PowerShell scripting and automation inquiries, it is recommended to post your questions on Microsoft Q&A using the appropriate Exchange and PowerShell tags, where Microsoft engineers can provide dedicated support.




