Skip to content
Email & Google WorkspaceBeginner

How to Restrict Email Communication to Approved Domains and Limit Attachment Size in Microsoft 365

Email remains one of the most common channels for data exchange—and also one of the most exploited attack vectors. Organizations handling financial, legal, o...

BI
Bison Technical Team Enterprise IT specialists
Updated 26 Dec 2025 3 min read 234 total views

Email remains one of the most common channels for data exchange—and also one of the most exploited attack vectors. Organizations handling financial, legal, or confidential information often need tight control over who can send emails to their users and where users can send emails.

Using Microsoft 365, administrators can enforce strict email communication policies through Exchange Online Mail Flow Rules (Transport Rules). This article explains the complete end-to-end process to:

Advertisement
  • Allow email communication only with approved external domains

  • Block all other external email traffic (incoming and outgoing)

  • Restrict email attachment size to 512 KB

  • Apply rules only to selected mailboxes


Use Case Scenario (Safe Example)

Mailboxes to be Protected

Approved External Domains

  • @partnerbank.example

  • @trustedvendor.example

Attachment Policy

  • Maximum allowed attachment size: 512 KB


Objectives of This Configuration

  • Prevent data leakage and accidental sharing

  • Reduce phishing and ransomware exposure

  • Enforce compliance and audit requirements

  • Control document flow via email

  • Secure high-risk or sensitive mailboxes


Prerequisites

Before starting, ensure:

  • You have Global Administrator or Exchange Administrator access

  • Mailboxes already exist in Microsoft 365

  • Approved domains list is finalized

  • Users are informed about upcoming restrictions


Step-by-Step Implementation Process


Step 1: Access Exchange Admin Center

  1. Log in to https://admin.microsoft.com

  2. Go to Admin Centers

  3. Click Exchange

  4. Navigate to Mail Flow → Rules


Step 2: Create Outgoing Email Restriction Rule

(Allow sending only to approved domains)

Rule Purpose

Blocks outgoing emails sent to any external domain except the approved list.

Rule Configuration

Rule Name:
Outgoing Restriction – Approved Domains Only

Apply this rule if:

Do the following:

  • Block the message

  • Reject with explanation:

    "Email sending is restricted to approved partner domains only."

Additional Settings:

  • Stop processing more rules: ✔ Enabled

  • Mode: Enforce

Result:
Users cannot send emails to any unapproved external domain.


Step 3: Create Incoming Email Restriction Rule

(Allow receiving only from approved domains)

Rule Purpose

Prevents unauthorized external senders from emailing protected mailboxes.

Rule Configuration

Rule Name:
Incoming Restriction – Approved Domains Only

Apply this rule if:

Do the following:

  • Block the message

  • Reject with explanation:

    "This mailbox accepts emails only from authorized partner domains."

Mode: Enforce

Result:
Only trusted external partners can send emails to these mailboxes.


Step 4: Create Attachment Size Restriction Rule

(Limit attachment size to 512 KB)

Rule Purpose

Prevents large file transfers via email.

Rule Configuration

Rule Name:
Attachment Limit – 512KB

Apply this rule if:

Do the following:

  • Block the message

  • Reject with explanation:

    "Attachments larger than 512 KB are not permitted. Please share files via secure links."

Mode: Enforce

Result:
Large files must be shared via OneDrive, SharePoint, or secure portals.


Step 5: Rule Priority Order (Very Important)

Ensure rules are ordered as follows:

  1. Outgoing restriction rule

  2. Incoming restriction rule

  3. Attachment size restriction rule

This avoids rule conflicts and ensures predictable behavior.


Step 6: Testing the Configuration

Test Scenarios

  • Send email to approved domain → Allowed

  • Send email to unapproved domain → Blocked

  • Receive email from approved domain → Allowed

  • Receive email from unapproved domain → Blocked

  • Send attachment >512 KB → Blocked

  • Send attachment <512 KB → Allowed

Optional: Use Audit mode first to monitor impact without blocking.


Best Practices

  • Maintain a documented approved domain list

  • Review rules quarterly

  • Educate users about restrictions

  • Use rejection messages that explain next steps

  • Combine with Microsoft Defender for Email

  • Enable message trace for troubleshooting


Common Business Use Cases

  • Banking and financial communications

  • Vendor invoice processing

  • Legal and compliance teams

  • Management and admin accounts

  • High-risk email addresses


Conclusion

By using Exchange Online mail flow rules, organizations can fully control email communication boundaries and file sharing behavior. Domain-restricted email access combined with strict attachment size limits provides a strong, simple, and effective email security posture in Microsoft 365—especially for sensitive or compliance-driven environments.


#Microsoft365 #ExchangeOnline #EmailSecurity #MailFlowRules #Office365Admin
#EmailCompliance #DomainRestriction #AttachmentLimit #CyberSecurity
#BusinessEmail #SecureEmail #EmailGovernance #ITSecurity #CloudSecurity
#MicrosoftAdmin #EmailPolicies #PhishingProtection #DataProtection
#EmailFiltering #SecureCommunication #EmailControl #InformationSecurity
#EmailHardening #CompliancePolicy #EnterpriseSecurity #EmailManagement
#MicrosoftSecurity #MailSecurity #BusinessIT #CloudEmail #EmailProtection
#EmailRisk #ExchangeAdmin #SecurityBestPractices #EmailRules #Office365Security
#MicrosoftExchange #EmailSafety #ITAdministration #SecurityAwareness

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

COMMUNITY NOTES

Reader feedback

1 comments
Community member

thank you for lovely article

BISON AI

Ask about “How to Restrict Email Communication to Approved Domains and Limit Attachment Size in Microsoft 365”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.