How can I avoid an exchange service to fall into a restricted entity in Microsoft 365

Ripio Developer 0 Reputation points
2025-02-12T21:13:56.0933333+00:00

I have a Microsoft 365 basic account. I am using an email from my account to send notifications and documents as attachments from an app that is located on an EC2 Amazon AWS. The problem I have is that the email account keeps falling under restricted entities; even though I have an MFA activated, have added the range of IP addresses from AWS as valid and use an app password, it repeatedly falls under restricted entities. Is there a way I can set a rule to avoid labelling it as spam and becoming restricted?

User's image

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,738 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
682 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,491 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Alex Zhang-MSFT 4,905 Reputation points Microsoft Vendor
    2025-02-13T06:48:01.8866667+00:00

    Hello, @Ripio Developer,

    Welcome to the Microsoft Q&A platform!

    There is not a rule that you can set in Microsoft 365 to tell its anti‐spam systems “never flag these messages.” Rather, it’s about configuring your sending environment so that Microsoft’s systems see your traffic as authenticated, authorized, and legitimate.

    Here are several approaches you can consider:

    1.Configure Anti-Spam Policies: You can create customized anti-spam policies in the Microsoft Defender portal to ensure that your emails are not marked as spam with the help of Configure spam filter policies - Microsoft Defender for Office 365 | Microsoft Learn. This involves setting specific rules for your AWS IP address or the email address used to send notifications.

    2.Use Safe Senders List: Add your sending email addresses to the Safe Senders list in Exchange Online according to Configure junk email settings on Exchange Online mailboxes - Microsoft Defender for Office 365 | Microsoft Learn. This can help ensure that emails from these addresses are not marked as spam.

    3.Check email content: The content of an email can trigger spam filters. Make sure your email does not contain elements that are usually associated with spam, such as too many links, certain keywords or large attachments.

    4.Monitor email sending patterns: Sending a large number of emails in a short period of time may trigger spam filters. Try to spread out your email sending time to avoid this problem.

    5.Use a dedicated Exchange Online connector or transactional email service: When you send notifications from AWS EC2 applications using Microsoft 365 email, there are no simple “rules” to bypass spam filters; you need to make sure your messages are authenticated! -- by setting up SPF, DKIM, and DMARC records -- and consider using a dedicated Exchange Online connector or transactional email service so that Microsoft recognizes your email as legitimate and authorized. and authorized.

    In summary, rather than a simple “rule” to whitelist outgoing messages, you’ll need to ensure that your sending configuration (through authentication, proper connectors, and volume management) is in line with Microsoft’s best practices. This way, your traffic will look legitimate to Microsoft’s security systems, reducing the risk of being flagged as spam.

    Should you need more help on this, you can feel free to post back. 


    If the answer is helpful, please click on “Accept answer” as it could help other members of the Microsoft Q&A community who have similar questions and are looking for solutions.

    Thank you for your support and understanding.

    Best Wishes,

    Alex Zhang

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.