How to Block Multiple Country-Code Domains in Microsoft 365 Email
Question details
Microsoft 365 administrators want to filter incoming emails by blocking or quarantining messages originating from specific foreign country-code top-level domains (ccTLDs) in bulk, rather than adding foreign domains individually.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- An administrator needs to enhance organizational email security by applying broad restrictions against selected country-code domains known for high spam or phishing volumes.
- Observed behavior
- The goal is to efficiently manage international domain restrictions via centralized policies like Exchange mail-flow rules or Microsoft Defender, avoiding the manual and tedious process of blocking individual domains.
Ensure you have Microsoft 365 global administrator or Exchange administrator privileges, and carefully evaluate your organization's legitimate international email traffic to prevent accidentally blocking essential correspondence.
Configure an Anti-Spam Policy in Microsoft Defender
Use the Microsoft Defender portal to create or modify an anti-spam policy that specifically targets and restricts emails from selected countries or regions.
Microsoft Defender provides a dedicated section for handling international spam. This is the most comprehensive method for tenant-wide protection.
Sign in to the Microsoft Defender portal at security.microsoft.com using your administrator credentials.
Go to 'Email & collaboration' > 'Policies & rules' > 'Threat policies'. Under the Policies section, click on 'Anti-spam'.
Select your existing anti-spam inbound policy (or create a new one) and click 'Edit allowed and blocked senders and domains'. Locate the 'International spam' section.
Enable the option to block emails from specific countries or regions, select the desired country codes from the list, and save your policy.
Create an Exchange Admin Center Mail-Flow Rule
Set up a custom mail-flow (transport) rule in Exchange Online to identify and redirect emails where the sender's address ends in specific top-level domains.
Use Outlook Junk Email Options (Client-Side)
Individual users can manage their own international domain blocks through the desktop Outlook application.
Looking for a Lightweight and Free Office Suite?
While configuring Microsoft 365 email security requires enterprise admin tools, your daily document creation doesn't need to be complex or expensive. WPS Office is a high-performance, free alternative to Microsoft Office, offering an intuitive interface and full file compatibility.
- 1. Download the Installer: Visit the official WPS website and download the free version for your operating system.
- 2. Install the Application: Run the setup file and follow the on-screen instructions to complete the fast installation.
- 3. Open Existing Documents: Launch WPS Office and directly open your existing Word, Excel, or PowerPoint files with zero formatting loss.

Frequently Asked Questions
Can I include multiple top-level domain endings in a single Exchange mail-flow rule?
Yes, when setting up an Exchange admin center mail-flow rule, you can add multiple domain endings or text patterns (such as .ru, .cn, .br) into the same condition block for efficient management.
What is the difference between blocking and quarantining foreign domains?
Blocking an email outright rejects it, meaning it will never be seen by the recipient. Quarantining holds the suspicious email in a secure portal where administrators or authorized users can review it, which helps prevent the loss of legitimate international messages.
Will blocking country-code domains block all spam from that country?
No. Many spammers operating internationally use generic domains like .com or .net. Blocking ccTLDs only stops emails originating from registered country-specific domains, so standard anti-spam policies are still essential.
How can I test an Exchange mail-flow rule without losing emails?
When creating a mail-flow rule in Exchange Online, you can set the 'Choose a mode for this rule' option to 'Test without Policy Tips'. This lets you track how many emails would be affected via message tracking logs without actively dropping the emails.




