logo
search
Security Policy Errors

How to Stop CEO Impersonation Emails with Exchange Rules

Maira MehtabMaira Mehtab Sep 24, 2026 870 views

Question details

The user wants to configure Exchange mail flow rules and anti-phishing controls to filter out external messages that falsely spoof the CEO's display name.

Product
Microsoft Exchange
Device & OS
not provided
Scenario
Protecting an organization's network from targeted spear-phishing and CEO impersonation attacks originating from external sources.
Observed behavior
Attackers are bypassing default filters by forging the CEO's display name on external emails to trick employees. The goal is to detect and redirect these malicious messages.
Before you start

Ensure you have administrator privileges in the Exchange Admin Center (EAC) to create, modify, and apply organizational mail flow rules.

Solution 1Recommended

Create a Mail Flow Rule for Display Name Filtering

Configure a specific Exchange mail flow rule to detect the CEO's name in email headers from external sources and redirect them for security review.

Because attackers can easily forge display names in their email clients, relying solely on sender addresses is insufficient. By creating a mail flow rule, you can actively scan message headers for your CEO's exact name and quarantine suspicious external emails before they reach your employees.

1
Access Exchange Admin Center

Log in to the Exchange Admin Center (EAC) using your administrator credentials and navigate to the 'Mail flow' > 'Rules' section.

2
Create a New Rule

Click the '+' icon to create a new rule and select 'Create a new rule...'. Name the rule something identifiable, such as 'CEO Impersonation Protection'.

3
Set the External Sender Condition

Under 'Apply this rule if...', select 'The sender is located...' and choose 'Outside the organization'.

4
Add the Display Name Condition

Click 'add condition', select 'A message header includes...', and specify the 'From' header. Enter the exact display name of your CEO as the text pattern to match.

5
Define the Action and Exceptions

Under 'Do the following...', choose to redirect the message to a monitored suspicious-mailbox address. Crucially, add an exception for 'The sender domain is...' and enter your organization's legitimate domains to ensure internal emails are not blocked.

Layered Security Approach: Display name filtering should always be combined with authenticated sender checks (SPF, DKIM, and DMARC) and dedicated anti-phishing policies to maximize organizational security.
Free Microsoft Office alternative

Looking for a Secure and Lightweight Office Suite? Try WPS Office

While you secure your organizational communications with Exchange rules, equip your team with a reliable, lightweight, and completely free office suite. WPS Office provides excellent compatibility with Microsoft formats and robust tools for daily productivity.

  1. 1. Visit the WPS Website: Navigate to the official WPS Office website to access the secure download page.
  2. 2. Download the Installer: Click the 'Free Download' button to get the installation package tailored for your operating system.
  3. 3. Install and Deploy: Run the installer, follow the on-screen prompts, and launch WPS Office to start working immediately.
Seamless compatibility with Microsoft Office formats (DOCX, XLSX, PPTX).Lightweight installation with minimal system resource consumption.Familiar, intuitive user interface ensuring a smooth migration for employees.Built-in PDF editing tools for secure and efficient document management.
microsoft office alternative - wps office

Frequently Asked Questions

Why is display name spoofing so common in phishing attacks?

Attackers exploit display name spoofing because many modern email clients only show the sender's display name by default on mobile devices and previews, making it easy to trick users into believing the email genuinely comes from a trusted executive.

Can mail flow rules block all impersonation attempts?

No single rule is foolproof. Mail flow rules act as a strong filter, but they must be combined with SPF, DKIM, DMARC, and Advanced Threat Protection (ATP) anti-phishing policies to provide comprehensive protection against evolving threats.

What happens to emails redirected by the mail flow rule?

Redirected emails are sent to the designated monitored mailbox or quarantine area you specify in the rule. Here, a security administrator can safely review the headers and intent of the email without exposing end users to the phishing attempt.

Should I create impersonation rules for other executives besides the CEO?

Yes, it is highly recommended to protect the names of all high-profile executives and key personnel—such as the CFO, HR Director, or IT Director—who have the authority to request sensitive information or financial transfers.