3 - Junk email and administrative quarantine
In this tutorial, you will learn how to deliver SUSPICIOUS
and BULK
messages to the users's junk email folder, and MALICIOUS
, SPAM
, and SPOOF
messages to the administrative quarantine (this requires an administrator to release the emails).
To create quarantine policies:
-
Open the Microsoft 365 Defender console ↗
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Rules, select Quarantine policies.
-
Select Add custom policy.
-
Set the Policy name to
UserNotifyAdminRelease
. -
Select Next.
-
In Recipient message access, select Set specific access (Advanced), and then:
- In Select release action preference, choose Allow recipients to request a message to be released from quarantine.
- In Select additional actions recipients can take on quarantined messages, select the Delete and Preview checkboxes.
-
Select Next.
-
In Quarantine notification, select Enable.
-
Select Next.
-
Review your settings and select Submit.
-
Select Done.
To configure quarantine notifications:
-
Open the Microsoft 365 Defender console ↗.
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Rules, select Quarantine policies.
-
Select Global settings.
-
Scroll to the bottom and set the desired frequency in Send end-user spam notifications every (days). This value can only be incremented in days.
-
Select Save.
To configure anti-spam policies:
-
Open the Microsoft 365 Defender console ↗.
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Policies, select Anti-spam.
-
Select the Anti-spam inbound policy (Default) text (not the checkbox).
-
In Actions, scroll down and select Edit actions.
-
Set the following conditions and actions (you might need to scroll up or down to find them):
- Spam: Move messages to Junk Email folder.
- High confidence spam: Quarantine message.
- Select quarantine policy: _UserNotifyAdminRelease_.
- Phishing: Quarantine message.
- Select quarantine policy: _UserNotifyAdminRelease_.
- High confidence phishing: Quarantine message.
- Select quarantine policy: _UserNotifyAdminRelease_.
- Retain spam in quarantine for this many days: Default is 15 days. Email Security recommends 15-30 days.
- Select the spam actions in the above step.
- Select Save.
To create the transport rules that will send emails with certain disposition to Email Security:
-
Open the new Exchange admin center ↗.
-
Go to Mail flow > Rules.
-
Select Add a Rule > Create a new rule.
-
Set the following rule conditions:
- Name: `Email Security Deliver to Junk Email folder`.
- Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-CFEmailSecurity-Disposition
> Save. - Enter words:
`SUSPICIOUS`, `BULK`
> Add > Save.
- Enter text:
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following - _Modify the message properties_ > _Set the Spam Confidence Level (SCL)_ > _5_.
-
Select Next.
-
You can use the default values on this screen. Select Next.
-
Review your settings and select Finish > Done.
-
Select the rule `Email Security Deliver to Junk Email folder` you have just created, and Enable.
-
Select Add a Rule > Create a new rule.
-
Set the following rule conditions:
- Name: `Email Security User Quarantine Message`.
- Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-CFEmailSecurity-Disposition
> Save. - Enter words: `MALICIOUS`, `UCE`, `SPOOF` > Add > Save.
- Enter text:
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following: _Modify the message properties_ > _Set the Spam Confidence Level (SCL)_ > _9_.
-
Select Next.
-
You can use the default values on this screen. Select Next.
-
Review your settings and select Finish > Done.
-
Select the rule `Email Security User Quarantine Message` you have just created, and select Enable.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Products
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark
-