Information
Messages sent from allowed safe list addresses bypass important security mechanisms, including spam filtering and sender authentication checks. Avoiding use of safe lists prevents potential threats from circumventing security mechanisms. While blocking all malicious senders is not feasible, blocking specific known, malicious IP addresses may reduce the threat from specific senders.
Solution
1. Sign in to Microsoft 365 Defender portal.
2. From the left-hand menu, find Email & collaboration and select Policies and Rules.
3. Select Threat Policies from the list of policy names.
4. Under Policies, select Anti-spam.
5. Select Connection filter policy (Default).
6. Click Edit connection filter policy.
7. (Optional) Enter addresses under Always block messages from the following IP addresses or address range as needed.
8. Ensure Turn on safe list is not selected.