How to Block External Emails Sent Through Power Automate Send an Email V3
Question details
The user needs to block external emails sent via the Power Automate Send an email (V3) connector using Exchange exfiltration rules.

- Product
- Power Automate / Exchange
- Device & OS
- not provided
- Scenario
- Preventing unauthorized email exfiltration to external domains via Power Automate automated flows.
- Observed behavior
- Existing Exchange mail flow rules successfully block the Send an email (V2) connector but fail to block messages sent through the Send an email (V3) connector because the two versions use different sender identities.
Ensure you have Exchange Administrator privileges to access the Exchange Admin Center and modify mail flow rules.
Configure an Exchange Mail Flow Rule using V3 Message Headers
Identify the unique sender address and headers used by the V3 connector, then create a specific Exchange rule to block these messages from reaching external recipients.
The Send an email (V2) and (V3) connectors use entirely different sender identities. While V2 sends emails acting as the user who triggered the flow, V3 typically sends from a generic Power Apps address. Because of this, rules designed for user identities will fail to catch V3 emails. Inspecting the internet headers of a V3 email allows you to pinpoint the exact sender address or unique X-headers to target in a new rule.
Create a test Power Automate flow using the Send an email (V3) connector to send an email to your own internal inbox. Open the received email, view its properties or message source, and locate the sender address (often a Power Apps address) and any unique identifying headers.
Log in to the Microsoft 365 Admin Center, navigate to the Exchange Admin Center, and select 'Mail flow' followed by 'Rules' from the left-hand menu.
Click the '+ Add a rule' button and select 'Create a new rule'. Give your rule a descriptive name, such as 'Block Power Automate V3 External Emails'.
Under 'Apply this rule if', select 'The sender...' and choose 'is this person' to enter the V3 sender address, or select 'A message header...' and 'includes any of these words' to target the unique header you found. Add a second condition for 'The recipient...' and choose 'is external/internal' set to 'Outside the organization'.
Under 'Do the following', select 'Block the message' and choose 'reject the message and include an explanation'. Enter a brief explanation for the sender.
Save the rule. Before enforcing it organization-wide, run additional tests using the V3 connector to ensure it successfully blocks external emails while allowing internal emails if desired.

Streamline Your Document Workflow with WPS Office
While managing Exchange rules and Power Automate flows requires administrative tools, your daily document handling shouldn't be complicated. WPS Office provides a robust, lightweight, and free alternative to Microsoft Office, ensuring seamless productivity without the heavy overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the installer and follow the on-screen prompts to complete the setup in just a few minutes.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Word, Excel, and PowerPoint files with perfect formatting preservation.

Frequently Asked Questions
Why does my Exchange rule block Send an email V2 but not V3?
The V2 connector sends emails using the identity of the user who triggered the flow, which matches standard exfiltration rules targeting user accounts. The V3 connector, however, sends messages from a generic Power Apps service address, causing it to bypass rules that strictly look for internal user sender identities.
How do I find the sender address for a Power Automate V3 email?
You can find the sender address by triggering a flow that sends a V3 email to your own inbox. Once received, open the email, access the message details or internet headers, and look for the 'From' or 'Sender' fields to identify the exact service address being used.
Will blocking the V3 connector affect internal company emails?
Not if configured correctly. When setting up your Exchange mail flow rule, make sure to add a condition that specifies the recipient must be 'Outside the organization'. This ensures internal automated emails continue to function normally while external exfiltration is blocked.




