Office 365 Whitelist
Use a Microsoft 365 allow policy only when your organization requires it for internal delivery testing or controlled receiving domains. Do not use whitelisting to bypass consent, suppression, or complaint handling.
Suggested checks
- Verify the sender domain first.
- Confirm SPF, DKIM, and DMARC alignment.
- Identify the receiving tenant and policy owner.
- Add only the required sender domain or IP range.
- Send a test message and inspect message trace.
Exact Microsoft admin center screens change often. Confirm the current path in Microsoft documentation before changing production tenant policy.