How to Stop Onmicrosoft Spam (2026 Complete Guide)
If you have a Microsoft 365, Outlook, or Hotmail email address, you have likely encountered spam messages sent from or through onmicrosoft.com domains. These spam emails can range from annoying marketing messages to potentially dangerous phishing attempts and scam campaigns. The onmicrosoft.com domain is associated with Microsoft’s cloud services, and unfortunately, spammers have found ways to exploit Microsoft 365 tenant configurations to send bulk spam that appears to come from legitimate Microsoft infrastructure. In this comprehensive 2026 guide, we will explain why you receive onmicrosoft spam, how to stop it using Microsoft’s built-in tools, and what additional measures you can take to protect your inbox from these unwanted messages.
Last updated: July 19, 2026 ยท Estimated reading time: 13 minutes
Table of Contents
- Understanding Onmicrosoft Spam
- Why You Receive Onmicrosoft Spam
- Step 1: Configure Outlook Junk Email Filter
- Step 2: Block Specific Senders and Domains
- Step 3: Set Up Exchange Transport Rules
- Step 4: Manage Safe Senders and Blocked Senders Lists
- Step 5: Report Spam to Microsoft
- Step 6: Enable Advanced Threat Protection
- Step 7: Check Your DNS and SPF Records
- Preventing Future Spam
- Frequently Asked Questions
Understanding Onmicrosoft Spam
The onmicrosoft.com domain is a default domain assigned to every Microsoft 365 tenant. When an organization signs up for Microsoft 365, they receive a subdomain of onmicrosoft.com (for example, contoso.onmicrosoft.com) that serves as their initial tenant identifier. This domain is used internally by Microsoft’s infrastructure and can also be used as a sender domain for emails sent through that tenant’s Exchange Online service.
Spammers exploit Microsoft 365 in several ways to send spam through onmicrosoft.com domains. The most common method is creating throwaway Microsoft 365 trial accounts or free Outlook accounts and using them to send bulk spam messages. Microsoft offers free trial periods for Microsoft 365 that provide full Exchange Online capabilities, and spammers create accounts, send thousands of spam messages during the trial period, and then abandon the accounts. Another method involves compromising legitimate Microsoft 365 accounts through phishing or credential theft and using those accounts to send spam that appears to come from a trusted source.
The challenge with onmicrosoft spam is that it often passes basic spam filters because it originates from Microsoft’s legitimate email infrastructure. The emails are sent through Microsoft’s servers, which have valid IP reputations and proper authentication records. This makes traditional spam filtering less effective because the messages do not trigger the same red flags as spam sent from known spam servers or compromised personal accounts on free email services.
Why You Receive Onmicrosoft Spam
Understanding the root cause of onmicrosoft spam helps you choose the most effective countermeasures. The reasons vary depending on whether you are an individual user, a business administrator, or someone who has had their email address exposed in a data breach.
Your Email Was Harvested by Spammers
The most common reason for receiving onmicrosoft spam is that your email address has been collected by spammers through data breaches, website scraping, or purchased email lists. If your email address appears on any public website, social media profile, or forum, it can be harvested by automated tools and added to spam distribution lists. Once your address is on these lists, you will receive spam from various sources, including onmicrosoft.com domains.
You Are Part of a Mass Spam Campaign
Spammers using Microsoft 365 trial accounts often send messages to millions of email addresses simultaneously, targeting random or semi-random address lists. You may receive onmicrosoft spam not because you were specifically targeted, but because your email address happened to be on a list that a spammer obtained. These campaigns are typically indiscriminate, sending the same spam message to every address on their list without any personal targeting.
Your Organization’s Tenant Is Compromised
If you are receiving onmicrosoft spam from your own organization’s domain or a known organization’s domain, it may indicate that a Microsoft 365 account within that tenant has been compromised. Attackers who gain access to a legitimate account can send spam and phishing messages that appear to come from a trusted source within the organization. This is a security concern that goes beyond simple spam and requires immediate attention. For information about detecting compromised devices on your network, see our guide on how to find out what device keeps disconnecting.
Step 1: Configure Outlook Junk Email Filter
The first and most immediate step to stop onmicrosoft spam is ensuring your Outlook junk email filter is properly configured. The junk filter is your first line of defense, and optimizing its settings can catch a significant percentage of unwanted messages.
Outlook Desktop App
Open Outlook and navigate to the Home tab. Click “Junk” in the Delete group, then select “Junk E-mail Options.” In the Options tab, set the protection level to “High” if you are receiving large volumes of spam, though be aware that this setting may also filter legitimate messages. The “Safe Senders Only” option is the most aggressive setting and will only allow messages from addresses and domains on your Safe Senders list. This is effective but requires you to maintain an accurate Safe Senders list to avoid missing legitimate emails.
In the Blocked Senders tab, add the onmicrosoft.com domain to block all emails from any address at that domain. Type @onmicrosoft.com in the Add field and click “Add.” This blocks all emails sent from any onmicrosoft.com address. If you need to allow specific onmicrosoft.com addresses while blocking the rest, add the individual addresses to your Safe Senders list and use the domain-level block for everything else.
Outlook Web (Outlook.com)
For Outlook.com or Microsoft 365 web users, click the gear icon in the top-right corner, then select “View all Outlook settings.” Navigate to Mail > Junk email. Under “Blocked senders and domains,” add @onmicrosoft.com to block the entire domain. You can also add individual spam sender addresses to this list. Under “Safe senders and domains,” add any legitimate onmicrosoft.com addresses that you want to continue receiving mail from.
Step 2: Block Specific Senders and Domains
Beyond the general junk filter, blocking specific senders and domains gives you granular control over what reaches your inbox. This is particularly useful for onmicrosoft spam where you can identify the specific tenant domains sending spam.
Blocking Domains in Outlook
In Outlook’s junk email options, the Blocked Senders tab allows you to add specific email addresses or entire domains. To block all emails from onmicrosoft.com, add the entry @onmicrosoft.com to the blocked senders list. This wildcard entry catches all emails from any address at that domain. You can also block specific subdomains, such as contoso.onmicrosoft.com, if you want to target a particular spamming tenant while allowing other onmicrosoft.com addresses.
Blocking in Outlook.com Web
Log into Outlook.com, open Settings, and navigate to the Junk email section. Under “Blocked senders and domains,” click “Add” and enter the addresses or domains you want to block. Outlook.com supports both individual address blocking and domain-level blocking. Changes take effect immediately and apply to all future incoming messages. Existing messages in your inbox or junk folder are not retroactively affected.
For organization administrators using Microsoft 365 Exchange Online, domain blocking can be configured at the tenant level using Exchange transport rules, which apply to all users in the organization. This is more efficient than requiring each user to configure their own blocking rules and ensures consistent spam protection across the entire organization.
Step 3: Set Up Exchange Transport Rules
For Microsoft 365 administrators, Exchange transport rules (also called mail flow rules) provide powerful organization-wide spam filtering capabilities. These rules can block, redirect, modify, or quarantine messages based on sender, recipient, content, and other criteria before they reach any user’s mailbox.
Creating a Transport Rule to Block Onmicrosoft Spam
Access the Exchange admin center at admin.exchange.microsoft.com. Navigate to Mail flow > Rules. Click “Add a rule” and select “Create a new rule.” Name the rule something descriptive like “Block Onmicrosoft Spam.” In the conditions section, set the rule to apply when “The sender’s domain is” and enter onmicrosoft.com. In the actions section, select “Block the message” and choose whether to reject the message with an NDR (non-delivery report) or silently delete it. Silent deletion is recommended for spam because it does not notify the spammer that their message was blocked.
For more targeted blocking, you can create rules that block specific subdomains while allowing others. This is useful when a particular Microsoft 365 tenant is sending spam but other onmicrosoft.com addresses are legitimate. The rule condition can target “The sender’s domain is” with a specific subdomain like spamtenant.onmicrosoft.com while leaving the broader onmicrosoft.com domain unblocked.
Anti-Spam Policy Adjustments
In the Microsoft 365 Defender portal (security.microsoft.com), navigate to Email & collaboration > Policies & rules > Threat policies > Anti-spam. Edit the inbound spam filter policy to increase spam confidence level (SCL) thresholds. Increasing the SCL threshold causes more messages to be classified as spam and routed to the junk folder. Be cautious with this adjustment as setting the threshold too aggressively can cause legitimate messages to be filtered incorrectly.
The Microsoft Defender portal also allows you to configure quarantine policies that determine what happens to messages flagged as spam. By default, high-confidence spam is quarantined, but you can adjust these settings to be more aggressive for specific types of spam. For guidance on identifying suspicious devices and network activity that may indicate compromise, see our article on finding devices that keep disconnecting.
Step 4: Manage Safe Senders and Blocked Senders Lists
Maintaining accurate Safe Senders and Blocked Senders lists is essential for effective spam management. These lists work in conjunction with the junk filter to give you precise control over what reaches your inbox.
Building Your Safe Senders List
Your Safe Senders list tells Outlook to always deliver messages from listed addresses, regardless of spam filter analysis. Add all contacts you correspond with regularly, important business contacts, newsletters you subscribe to, and any legitimate onmicrosoft.com addresses you need to receive. This ensures that even aggressive spam filtering settings do not block messages from trusted sources. The Safe Senders list can be managed through Outlook’s junk email options or through the Outlook.com settings page.
Maintaining Your Blocked Senders List
Regularly review and update your Blocked Senders list to add new spam addresses and remove entries that are no longer relevant. Spammers frequently change sender addresses to evade blocking, so the Blocked Senders list requires ongoing maintenance to remain effective. If you notice a pattern in the spam you receive (such as a common phrase in the subject line or body), you can also use Outlook’s junk email options to create rules based on message content rather than just sender addresses.
Step 5: Report Spam to Microsoft
Reporting spam to Microsoft helps their filtering systems learn and improve, reducing the volume of spam that reaches all users. Microsoft uses reports from users to train their machine learning-based spam filters and to identify new spam campaigns targeting Microsoft 365 infrastructure.
Reporting Through Outlook
In the Outlook desktop app, select the spam message and click “Junk” in the Home tab, then select “Report as Junk” or “Report as Phishing.” This sends a report to Microsoft and simultaneously moves the message to your junk folder and adds the sender to your blocked senders list. For messages that are clearly phishing attempts (attempting to steal credentials or install malware), always use “Report as Phishing” rather than “Report as Junk” as this provides more detailed information to Microsoft’s security teams.
In Outlook.com, select the message, click the junk button (exclamation mark icon), and select “Report junk” or “Report phishing.” The reporting mechanism works the same way, sending telemetry to Microsoft while configuring your local junk filter to block future messages from the sender.
Reporting Through Microsoft Defender
Microsoft 365 administrators can report spam campaigns through the Microsoft Defender portal. If you identify a systematic spam campaign originating from onmicrosoft.com domains, report it through the submission portal at security.microsoft.com. This escalates the issue to Microsoft’s abuse team, who can investigate the offending tenant and potentially disable it to prevent further spam. This is the most effective way to address large-scale spam campaigns rather than just blocking individual messages.
Step 6: Enable Advanced Threat Protection
Microsoft 365 offers several advanced security features that provide additional layers of spam and phishing protection beyond the basic junk filter. These features are available in Microsoft 365 Business Premium, E3, and E5 subscriptions and can significantly reduce the amount of spam reaching your inbox.
Microsoft Defender for Office 365
Microsoft Defender for Office 365 (formerly Office 365 Advanced Threat Protection) provides safe attachments, safe links, anti-phishing policies, and sophisticated spam filtering. The anti-phishing policies use machine learning to analyze message characteristics and identify spam and phishing attempts that traditional rules might miss. Enable all of these features through the Microsoft Defender portal to provide comprehensive protection against onmicrosoft spam campaigns.
The safe attachments feature detaches email attachments and scans them in a sandbox environment before delivering them to the recipient. This prevents malware-laden attachments from reaching users even if the spam filter fails to identify the message as spam. Safe links protection scans URLs in email messages at the time of click, blocking access to known malicious websites even if the URL was not flagged when the email was originally sent.
Exchange Online Protection Enhancements
Exchange Online Protection (EOP) is included with all Microsoft 365 subscriptions and provides baseline spam filtering. Enhance EOP’s effectiveness by configuring connection filtering to block known spam IP addresses, enabling bulk complaint level (BCL) filtering to catch mass-marketing emails, and adjusting the spam filter sensitivity settings. These configurations are managed through the Exchange admin center or Microsoft Defender portal and apply to all mail flow through the tenant. For information about disabling invasive tracking features on Dell systems, see our guide on how to disable face recognition on Dell laptop.
Step 7: Check Your DNS and SPF Records
If you are a domain administrator and you are finding that your domain is being used to send spam (or that your legitimate emails are being flagged as spam), checking and configuring your DNS records is essential. Proper DNS configuration helps email providers distinguish between legitimate messages from your domain and spoofed messages sent by spammers.
SPF, DKIM, and DMARC
SPF (Sender Policy Framework) records tell receiving mail servers which IP addresses are authorized to send email on behalf of your domain. An SPF record that lists only your legitimate mail servers prevents spammers from spoofing your domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing messages that receiving servers can verify, confirming the message was actually sent by your domain and was not modified in transit.
DMARC (Domain-based Message Authentication, Reporting & Conformance) builds on SPF and DKIM by telling receiving servers what to do when a message fails authentication checks. A DMARC policy of “reject” causes receiving servers to reject messages that fail SPF and DKIM checks entirely, preventing them from reaching any recipient’s inbox. Configure DMARC with a policy of “none” initially to gather data, then move to “quarantine” and finally “reject” once you are confident that legitimate email is properly authenticated.
Preventing Future Spam
Stopping onmicrosoft spam requires both reactive measures (blocking current spam) and proactive measures (preventing future spam). The following strategies help minimize the volume of spam you receive over time.
Never publish your email address in plain text on public websites, forums, or social media. Use contact forms instead of posting email addresses directly. If you must display an email address publicly, consider using an image of the text rather than a clickable mailto link, or use a disposable email address for public-facing communications. Spammers use web scraping tools to harvest email addresses from any publicly accessible page.
Use a unique email address for each purpose (one for banking, one for shopping, one for social media, one for public use). When spam starts arriving at a specific address, you know which service was compromised and can update your email address at that service while keeping your other addresses clean. Microsoft 365 and Outlook.com support plus addressing (adding a tag before the @ symbol, such as [email protected]) which allows you to create unique addresses without creating separate accounts.
Enable two-factor authentication (2FA) on your Microsoft 365 and Outlook accounts. Compromised accounts are often used to send spam, and 2FA prevents unauthorized access even if your password is stolen. Use the Microsoft Authenticator app or a hardware security key for the strongest protection. Regularly review your account’s sign-in activity at account.live.com/ACXT to identify any unauthorized access attempts. For more information about protecting your devices and accounts, see our guide on whether trojans can work without internet.
Frequently Asked Questions
Why am I getting so much spam from onmicrosoft.com addresses?
Onmicrosoft.com spam typically increases when spammers create trial Microsoft 365 accounts to send bulk messages, or when they compromise legitimate Microsoft 365 accounts. The onmicrosoft.com domain is Microsoft’s default tenant domain, and emails sent through Microsoft 365 infrastructure often pass basic spam filters because they originate from legitimate Microsoft servers. The best approach is to block the @onmicrosoft.com domain in your junk email settings if you do not need to receive legitimate emails from Microsoft 365 tenants, and to report the spam to Microsoft for investigation.
Can I block all emails from onmicrosoft.com in Outlook?
Yes. In Outlook, go to Home > Junk > Junk E-mail Options > Blocked Senders tab, and add @onmicrosoft.com to the list. This blocks all emails from any address at the onmicrosoft.com domain. In Outlook.com, go to Settings > View all Outlook settings > Mail > Junk email and add @onmicrosoft.com to the blocked senders list. If you need to receive emails from specific onmicrosoft.com addresses (such as from your organization or a business partner), add those addresses to your Safe Senders list to override the domain-level block.
Is onmicrosoft spam dangerous?
Some onmicrosoft spam is simply marketing or advertising material, which is annoying but not directly dangerous. However, onmicrosoft spam can also include phishing attempts that try to steal your login credentials, malware attachments that can infect your computer, and scam messages that attempt to defraud you. Treat all unsolicited onmicrosoft emails with caution. Never click links or open attachments in messages you were not expecting, even if they appear to come from a legitimate organization. For information about malware that can operate offline, see our article on whether trojans work without internet.
How do I stop spam in Outlook without blocking legitimate emails?
Use Outlook’s junk email filter at the “Low” or “Medium” setting, which catches obvious spam while allowing borderline messages through. Maintain an accurate Safe Senders list with all your important contacts and trusted senders. Instead of blocking the entire onmicrosoft.com domain, block specific sender addresses that are sending spam while adding legitimate onmicrosoft.com addresses to your Safe Senders list. This provides a balance between spam reduction and ensuring you do not miss important emails.
Does Microsoft do anything about onmicrosoft spam?
Microsoft actively investigates and takes action against Microsoft 365 tenants that are used for spam. When users report spam through Outlook or the Microsoft Defender portal, Microsoft reviews the reports and can disable offending tenants, suspend accounts, and take legal action against abusers. However, the volume of spam is enormous, and spammers constantly create new accounts. User reporting is an important part of the process because it helps Microsoft identify and respond to new spam campaigns more quickly.
Can I create a rule to automatically delete onmicrosoft spam?
Yes. In Outlook, you can create rules that automatically move or delete messages from specific domains. Go to Home > Rules > Create Rule, or use the Advanced Rules editor for more complex conditions. Set the condition to “with specific words in the sender’s address” and enter onmicrosoft.com. Set the action to “delete it” or “move it to the Deleted Items folder.” For Microsoft 365 administrators, Exchange transport rules can be configured to automatically delete messages from onmicrosoft.com domains at the server level, preventing them from reaching any user’s mailbox.
Why are legitimate emails being flagged as spam when they come from onmicrosoft.com?
If you have blocked the entire onmicrosoft.com domain, all messages from that domain will be filtered to junk, including legitimate ones. To fix this, add the specific legitimate onmicrosoft.com addresses to your Safe Senders list, which overrides the domain-level block. If you have not blocked the domain but are still seeing legitimate onmicrosoft emails in junk, the spam filter may be flagging them due to content analysis, sender reputation, or other factors. Check your junk email options and Safe Senders list to ensure legitimate senders are properly whitelisted.
Will changing my email address stop onmicrosoft spam?
Getting a new email address will temporarily stop the spam, but if your new address eventually gets harvested by spammers through data breaches or web scraping, the spam will resume. A more sustainable approach is to keep your primary email address private, use disposable aliases for public-facing situations, and configure robust spam filtering on your existing account. Microsoft 365 and Outlook.com support email aliases that allow you to create additional addresses without creating new accounts, giving you a way to compartmentalize your email usage without the hassle of managing multiple accounts. For tips on securing your accounts and devices, see our guide on disabling face recognition on Dell laptops.




