How to Stop CEO Impersonation Emails with Exchange Rules
Question details
The user wants to configure Exchange mail flow rules and anti-phishing controls to filter out external messages that falsely spoof the CEO's display name.
- Product
- Microsoft Exchange
- Device & OS
- not provided
- Scenario
- Protecting an organization's network from targeted spear-phishing and CEO impersonation attacks originating from external sources.
- Observed behavior
- Attackers are bypassing default filters by forging the CEO's display name on external emails to trick employees. The goal is to detect and redirect these malicious messages.
Ensure you have administrator privileges in the Exchange Admin Center (EAC) to create, modify, and apply organizational mail flow rules.
Create a Mail Flow Rule for Display Name Filtering
Configure a specific Exchange mail flow rule to detect the CEO's name in email headers from external sources and redirect them for security review.
Because attackers can easily forge display names in their email clients, relying solely on sender addresses is insufficient. By creating a mail flow rule, you can actively scan message headers for your CEO's exact name and quarantine suspicious external emails before they reach your employees.
Log in to the Exchange Admin Center (EAC) using your administrator credentials and navigate to the 'Mail flow' > 'Rules' section.
Click the '+' icon to create a new rule and select 'Create a new rule...'. Name the rule something identifiable, such as 'CEO Impersonation Protection'.
Under 'Apply this rule if...', select 'The sender is located...' and choose 'Outside the organization'.
Click 'add condition', select 'A message header includes...', and specify the 'From' header. Enter the exact display name of your CEO as the text pattern to match.
Under 'Do the following...', choose to redirect the message to a monitored suspicious-mailbox address. Crucially, add an exception for 'The sender domain is...' and enter your organization's legitimate domains to ensure internal emails are not blocked.
Looking for a Secure and Lightweight Office Suite? Try WPS Office
While you secure your organizational communications with Exchange rules, equip your team with a reliable, lightweight, and completely free office suite. WPS Office provides excellent compatibility with Microsoft formats and robust tools for daily productivity.
- 1. Visit the WPS Website: Navigate to the official WPS Office website to access the secure download page.
- 2. Download the Installer: Click the 'Free Download' button to get the installation package tailored for your operating system.
- 3. Install and Deploy: Run the installer, follow the on-screen prompts, and launch WPS Office to start working immediately.

Frequently Asked Questions
Why is display name spoofing so common in phishing attacks?
Attackers exploit display name spoofing because many modern email clients only show the sender's display name by default on mobile devices and previews, making it easy to trick users into believing the email genuinely comes from a trusted executive.
Can mail flow rules block all impersonation attempts?
No single rule is foolproof. Mail flow rules act as a strong filter, but they must be combined with SPF, DKIM, DMARC, and Advanced Threat Protection (ATP) anti-phishing policies to provide comprehensive protection against evolving threats.
What happens to emails redirected by the mail flow rule?
Redirected emails are sent to the designated monitored mailbox or quarantine area you specify in the rule. Here, a security administrator can safely review the headers and intent of the email without exposing end users to the phishing attempt.
Should I create impersonation rules for other executives besides the CEO?
Yes, it is highly recommended to protect the names of all high-profile executives and key personnel—such as the CFO, HR Director, or IT Director—who have the authority to request sensitive information or financial transfers.




