---
title: Manage Allowed Email Senders and Domains
description: Use this operation to add or remove email senders, domains, and IP addresses from the Tenant Allow/Block list in Microsoft Defender for Email.
---

[Skip to content](https://knowledge.sittadel.com/manage-allowed-email-senders-and-domains#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [TechOps](https://knowledge.sittadel.com/techops?hsLang=en)
3. [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)

# Manage Allowed Email Senders and Domains

## Use this operation to add or remove email senders, domains, and IP addresses from the Tenant Allow/Block list in Microsoft Defender for Email.

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-04-16-2156-PM.png?width=125&height=133&name=image-png-Jan-19-2024-04-04-16-2156-PM.png)Role Requirements**

Procedure Scope: **Administrators**

Required Group Membership: **Admin.Security**

### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-13-05-5511-PM.png?width=125&height=148&name=image-png-Jan-19-2024-04-13-05-5511-PM.png)

### **Handbook Reference**

Package: **Email Security**

Domain: **Sender Allowance Management**

Modifies: **Allowed Tenant Senders and Domains, Allowed Tenant IP Addresses, Allowed Spoofed Senders and Domains, Allowed Spam Senders and Domains, Allowed Impersonation Senders and Domains **

### ![2024-12-17\_9-49-52](https://knowledge.sittadel.com/hs-fs/hubfs/Canva%20images/2024-12-17_9-49-52.png?width=125&height=103&name=2024-12-17_9-49-52.png)

### **When to Perform this Operation**

As Needed: **Proactive or in Response to User/Security**

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Technical Description and Importance

Managing allowed email senders and domains ensures that essential communications are not blocked by security filtering mechanisms. This process enables organizations to maintain proper email functionality while reducing disruptions caused by false positives. By selectively allowing senders, domains, and IP addresses, organizations can enhance email security while maintaining necessary business operations. Continuous management of these lists helps prevent operational delays while aligning with email security configurations.

### Management Options

- [Allow a Sender or Domain](https://knowledge.sittadel.com/manage-allowed-email-senders-and-domains#Allow-a-Sender-or-Domain)
- [Allow an IPv6 Address](https://knowledge.sittadel.com/manage-allowed-email-senders-and-domains#Allow-an-IPv6-Address)
- [Allow a Spoofed Sender or Domain](https://knowledge.sittadel.com/manage-allowed-email-senders-and-domains#Allow-a-Spoofed-Sender-or-Domain)
- [Allow a Spam Sender or Domain](https://knowledge.sittadel.com/manage-allowed-email-senders-and-domains#Allow-a-Spam-Sender-or-Domain)
- [Allow an Impersonation Sender or Domain](https://knowledge.sittadel.com/manage-allowed-email-senders-and-domains#Allow-an-Impersonation-Sender-or-Domain)

#### ![2024-12-17\_10-15-21](https://knowledge.sittadel.com/hs-fs/hubfs/2024-12-17_10-15-21.png?width=670&height=81&name=2024-12-17_10-15-21.png)

#### Allow a Sender or Domain:

> **Purpose**  
> *Add an email sender or domain to the allow list in Defender for Email to prevent filtering.*  
> **Use Case**  
> *A trusted partner’s emails are being incorrectly marked as spam, requiring an explicit allow entry.*

#### Allow an IPv6 Address:

> **Purpose**  
> *Add an IPv6 address to the allow list in Defender for Email to permit messages from a specific mail server.*  
> **Use Case**  
> *A known mail server with a static IPv6 address is being blocked, and mail flow must be restored.*

#### Allow a Spoofed Sender or Domain:

> **Purpose**  
> *Allow a sender or domain that appears to be spoofed but is authorized for specific business needs.*  
> **Use Case**  
> *A legitimate service provider is sending email on behalf of an internal domain, triggering spoof detection.*

#### Allow a Spam Sender or Domain:

> **Purpose**  
> *Add a sender or domain to the allowed spam list to prevent filtering based on spam detection.*  
> **Use Case**  
> *A bulk email sender (such as a newsletter service) is being marked as spam but is required for business communications.*

#### Allow an Impersonation Sender or Domain:

> **Purpose**  
> *Add a sender or domain to the allowed impersonation list to prevent filtering based on impersonation/anti-phishing detection.*  
> **Use Case**  
> *A mail relay service using a lookalike domain is being marked as impersonation but is required for business communications.*

*![2024-12-17\_10-15-21-1](https://knowledge.sittadel.com/hs-fs/hubfs/2024-12-17_10-15-21-1.png?width=670&height=81&name=2024-12-17_10-15-21-1.png)*

| ###### **Operation** | ###### **Action** | ###### **Target** |
| --- | --- | --- |
| Allow a Sender or Domain | **Addition** | Allowed Tenant Senders and Domains |
| Allow an IPv6 Address | **Addition** | Allowed Tenant IP Addresses |
| Allow a Spoofed Sender or Domain | **Addition** | Allowed Spoofed Senders and Domains |
| Allow a Spam Sender or Domain | **Addition** | Allowed Spam Senders and Domains |
| Allow an Impersonation Senders and Domains | **Addition** | Allowed Impersonation Senders and Domains |

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### **Allow a Sender or Domain**

This operation adds a sender or domain to the allowlist, ensuring their emails bypass filtering mechanisms.

**       1. Defender for Email Submit and Allow Action**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-email-submit-and-allow-action#Procedure" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### **Allow an IPv6 Address**

This operation adds an IPv6 address to the allow list in Defender for Email, ensuring mail servers using the address can send email without restriction.

**       1. Defender for Email IP Address Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-email-ip-address-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### **Allow a Spoofed Sender or Domain**

This operation allows a spoofed sender or domain in Defender for Email, preventing it from being blocked based on spoofing detection.

**       1. Defender for Email Spoof Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-email-spoof-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### **Allow a Spam Sender or Domain**

This operation adds a sender or domain to the spam allow list in Defender for Email, preventing its messages from being marked as spam.

**       1. Defender for Email Spam Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-email-spam-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### **Allow an Impersonation Sender or Domain**

This operation adds a sender or domain to the impersonation allow list in Defender for Email, preventing its messages from being marked as impersonation.

**       1. Defender for Email Impersonation Allowance**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-for-email-impersonation-allowance#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>