# Review outbound malware handling separately from custom inbound mail policies

> Does a custom anti-malware policy configure protection for mail leaving a cloud mailbox?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:20+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does a custom anti-malware policy configure protection for mail leaving a cloud mailbox?

## Potentially affected

Organizations reviewing anti-malware policy settings for cloud mailboxes and outbound messages.

## DSE recommendation

Give outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy.

## Article

## Source facts

Microsoft distinguishes mail direction: the default anti-malware policy covers inbound and outbound messages, while custom anti-malware policies cover inbound messages only. The default policy cannot be disabled. Administrator notifications described in this configuration guide are sent only for attachments classified as malware. Those boundaries matter when someone expects a custom-policy change or an absent notification to describe outgoing protection. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure).

## Applicability

Review cloud-mailbox anti-malware configuration, not an assumption about a different message protection feature. Identify the sending mailbox, recipient direction, policy being edited, and notification setting. Keep a custom policy’s recipient targeting separate from the outgoing-mail question.

## DSE recommendation

Give outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy. Have the messaging owner document the intended outgoing action and the administrator who should receive relevant notifications. Review the actual classification when a notice is absent; do not use notification volume alone as a measure of protection.

## Verification

Plan separately approved internal-to-internal, internal-to-external, and external-to-internal tests using Microsoft’s documented safe-testing guidance. Preserve direction, effective settings, message outcome, classification, and expected notification recipient for each case. Investigate any mismatch before changing notification recipients or adding more custom policies. Keep the outcome evidence tied to the tested flow so an inbound success is not reused as the outbound acceptance record.

## Official references

[Microsoft Learn: Configure anti-malware policies for cloud mailboxes](https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure anti-malware policies for email - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review outbound malware handling separately from custom inbound mail policies,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
