logo
search
Others

Fix Exchange Online Transport Rule Wrapping Protected Emails as Attachments

Rana GarciaRana Garcia Sep 27, 2026 870 views

Question details

The user needs to prevent an Exchange Online transport rule from converting protected or encrypted external emails into file attachments due to a WRAP fallback action, without having to manually exclude a massive list of domains.

How to Stop Exchange Online Transport Rules from Wrapping Protected Emails
Product
Exchange Online
Device & OS
not provided
Scenario
Applying a transport rule in Exchange Online that adds a disclaimer or banner to external incoming emails.
Observed behavior
When external emails are encrypted or protected, the transport rule cannot inject the banner into the body. Instead, it triggers a WRAP fallback action, causing the secure message to arrive as an attachment.
Before you start

Ensure you have Microsoft Exchange Administrator permissions and verify if your organization strictly requires external banners on all incoming encrypted messages.

Solution 1Recommended

Exclude Encrypted Messages from the Transport Rule

Modify the transport rule exceptions to bypass protected or encrypted messages, preventing the WRAP fallback action from triggering.

Because Exchange cannot modify the body of an encrypted or digitally signed message to append a banner, it wraps the message in a new envelope. By adding an exception for protected messages, you ensure they are delivered normally without the banner.

1
Open Exchange Admin Center

Sign in to the Microsoft 365 Exchange Admin Center (EAC) using your administrator credentials.

2
Navigate to Rules

On the left navigation pane, go to 'Mail flow' and select 'Rules'.

3
Edit the External Banner Rule

Select the transport rule responsible for adding the external email banner and click 'Edit rule conditions'.

4
Add an Exception for Protected Messages

Scroll down to the 'Except if' section. Add a new exception for message types, such as 'The message properties include the message type > Permission controlled', or check for specific OME (Office 365 Message Encryption) headers.

5
Save and Test

Save the transport rule changes. Send a test encrypted email from an external domain to verify it arrives directly in the inbox instead of as an attachment.

Exclude Encrypted Messages from the Transport Rule
Exception Applied Successfully: Using a blanket exception for encrypted messages eliminates the need to maintain an impractical, constantly growing list of excluded domains.
Free Microsoft Office alternative

Try WPS Office for a Seamless Productivity Experience

While you are managing complex Exchange Online server configurations, it is also important to equip your users with efficient desktop productivity tools. WPS Office is a lightweight, free alternative to Microsoft Office that meets everyday documentation, spreadsheet, and presentation needs with zero learning curve.

Fully compatible with Microsoft Word, Excel, and PowerPoint formatsFamiliar ribbon interface ensures seamless migration for Office usersLightweight application with low system resource consumptionBuilt-in robust PDF editing and conversion toolsFree to use for essential business productivity tasks
microsoft office alternative - wps office

Frequently Asked Questions

Why does Exchange Online use a WRAP fallback action for protected emails?

When a transport rule attempts to modify an email (such as appending an HTML disclaimer) that is encrypted or digitally signed, it cannot alter the original message body without breaking the encryption. Instead, the fallback action wraps the original message inside a new envelope so the disclaimer can be applied to the outer envelope.

How can I tell which transport rule is wrapping my messages as attachments?

You can use the Message Trace tool in the Exchange Admin Center. By viewing the detailed events of a delivered message, you can see exactly which transport rules evaluated the email and which one triggered the fallback action.

Can I force Exchange to inject HTML banners into encrypted emails?

No. Due to the nature of encryption, the message body is cryptographically secured. Exchange cannot inject plain text or HTML directly into the protected payload. You must choose to reject the message, ignore the rule, or wrap it as an attachment.