{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
        "slug": "dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/"
        },
        "title": "Account for every recipient when a tenant sender block rejects outbound mail",
        "summary": "Can one blocked recipient cause a message to fail for its other internal and external recipients?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:44+00:00",
        "modified_at": "2026-09-10T00:55:36+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 249,
        "potentially_affected": "Microsoft 365 Tenant Allow/Block List domain and email-address block entries, excluding the separate spoofed-sender pair workflow.",
        "dse_recommendation": "Review the outbound recipient impact of a domain or address block before treating it solely as inbound protection.",
        "primary_source": {
            "name": "Allow or block email using the Tenant Allow/Block List - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-email-spoof-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Tenant Allow/Block List domain and email-address blocks quarantine incoming messages from those senders as high-confidence phishing. They also prevent organizational users from sending to the blocked destinations. The documented outbound rejection is 550 5.7.703. If even one recipient matches a block entry, the entire message is blocked for all its internal and external recipients. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-email-spoof-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This concerns ordinary domain and email-address block entries, not the separate spoofed-sender pairing mechanism. Review it when a protective block unexpectedly disrupts a conversation containing additional recipients.</p>\n<h2>DSE recommendation</h2>\n<p>Review the outbound recipient impact of a domain or address block before treating it solely as inbound protection. During an incident, preserve the reason for the block while explaining its wider effect to the mail owner. For a rejected multi-recipient message, reconcile the full intended recipient set rather than assuming that everyone except the blocked destination received a copy. Any resend should follow the approved response decision, not automatically remove the protective entry.</p>\n<h2>Verification</h2>\n<p>Compare the non-delivery report with the exact configured entry and the original recipient list. In an authorized test, use safe controlled addresses to verify the expected all-recipient rejection without contacting a suspected malicious destination. Document the recipients requiring an approved alternate communication and whether that communication was actually completed. Keep the block&#8217;s security rationale separate from the delivery recovery record so neither successful resending nor a help-desk closure is mistaken for removal of the underlying threat.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-email-spoof-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Tenant domain and address blocks</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nTenant Allow/Block List domain and email-address blocks quarantine incoming messages from those senders as high-confidence phishing. They also prevent organizational users from sending to the blocked destinations. The documented outbound rejection is 550 5.7.703. If even one recipient matches a block entry, the entire message is blocked for all its internal and external recipients. Microsoft Learn.\nApplicability\nThis concerns ordinary domain and email-address block entries, not the separate spoofed-sender pairing mechanism. Review it when a protective block unexpectedly disrupts a conversation containing additional recipients.\nDSE recommendation\nReview the outbound recipient impact of a domain or address block before treating it solely as inbound protection. During an incident, preserve the reason for the block while explaining its wider effect to the mail owner. For a rejected multi-recipient message, reconcile the full intended recipient set rather than assuming that everyone except the blocked destination received a copy. Any resend should follow the approved response decision, not automatically remove the protective entry.\nVerification\nCompare the non-delivery report with the exact configured entry and the original recipient list. In an authorized test, use safe controlled addresses to verify the expected all-recipient rejection without contacting a suspected malicious destination. Document the recipients requiring an approved alternate communication and whether that communication was actually completed. Keep the block’s security rationale separate from the delivery recovery record so neither successful resending nor a help-desk closure is mistaken for removal of the underlying threat.\nOfficial references\nMicrosoft Learn: Tenant domain and address blocks. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nTenant Allow/Block List domain and email-address blocks quarantine incoming messages from those senders as high-confidence phishing. They also prevent organizational users from sending to the blocked destinations. The documented outbound rejection is 550 5.7.703. If even one recipient matches a block entry, the entire message is blocked for all its internal and external recipients. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-email-spoof-configure).\n\n## Applicability\n\nThis concerns ordinary domain and email-address block entries, not the separate spoofed-sender pairing mechanism. Review it when a protective block unexpectedly disrupts a conversation containing additional recipients.\n\n## DSE recommendation\n\nReview the outbound recipient impact of a domain or address block before treating it solely as inbound protection. During an incident, preserve the reason for the block while explaining its wider effect to the mail owner. For a rejected multi-recipient message, reconcile the full intended recipient set rather than assuming that everyone except the blocked destination received a copy. Any resend should follow the approved response decision, not automatically remove the protective entry.\n\n## Verification\n\nCompare the non-delivery report with the exact configured entry and the original recipient list. In an authorized test, use safe controlled addresses to verify the expected all-recipient rejection without contacting a suspected malicious destination. Document the recipients requiring an approved alternate communication and whether that communication was actually completed. Keep the block’s security rationale separate from the delivery recovery record so neither successful resending nor a help-desk closure is mistaken for removal of the underlying threat.\n\n## Official references\n\n[Microsoft Learn: Tenant domain and address blocks](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-email-spoof-configure). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Account for every recipient when a tenant sender block rejects outbound mail",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/",
                "headline": "Account for every recipient when a tenant sender block rejects outbound mail",
                "description": "Can one blocked recipient cause a message to fail for its other internal and external recipients?",
                "abstract": "Can one blocked recipient cause a message to fail for its other internal and external recipients?",
                "articleBody": "Source facts\nTenant Allow/Block List domain and email-address blocks quarantine incoming messages from those senders as high-confidence phishing. They also prevent organizational users from sending to the blocked destinations. The documented outbound rejection is 550 5.7.703. If even one recipient matches a block entry, the entire message is blocked for all its internal and external recipients. Microsoft Learn.\nApplicability\nThis concerns ordinary domain and email-address block entries, not the separate spoofed-sender pairing mechanism. Review it when a protective block unexpectedly disrupts a conversation containing additional recipients.\nDSE recommendation\nReview the outbound recipient impact of a domain or address block before treating it solely as inbound protection. During an incident, preserve the reason for the block while explaining its wider effect to the mail owner. For a rejected multi-recipient message, reconcile the full intended recipient set rather than assuming that everyone except the blocked destination received a copy. Any resend should follow the approved response decision, not automatically remove the protective entry.\nVerification\nCompare the non-delivery report with the exact configured entry and the original recipient list. In an authorized test, use safe controlled addresses to verify the expected all-recipient rejection without contacting a suspected malicious destination. Document the recipients requiring an approved alternate communication and whether that communication was actually completed. Keep the block’s security rationale separate from the delivery recovery record so neither successful resending nor a help-desk closure is mistaken for removal of the underlying threat.\nOfficial references\nMicrosoft Learn: Tenant domain and address blocks. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:28:44+00:00",
                "dateModified": "2026-09-10T00:55:36+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-192-account-for-every-recipient-when-a-tenant-sender-block-rejects-outbound-mail/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Account for every recipient when a tenant sender block rejects outbound mail"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 249,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Allow or block email using the Tenant Allow/Block List - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-email-spoof-configure"
                }
            }
        ]
    }
}