Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails

Posted on August 23, 2025August 23, 2025 By CWS

Microsoft has introduced vital restrictions on electronic mail sending capabilities for organizations utilizing default onmicrosoft.com domains, implementing a throttling system that limits exterior electronic mail supply to 100 recipients per group each 24 hours. 

The coverage change, introduced via the Change Group Weblog, goals to forestall spam abuse whereas encouraging organizations emigrate to customized domains for improved electronic mail deliverability and model illustration.

Key Takeaways1. Microsoft limits onmicrosoft.com domains to 100 exterior emails each day.2. Targets cybercriminals exploiting new tenants, defending shared area status.3. Organizations should buy customized domains, rollout phases via June 2026.

Electronic mail Throttling Imposed

Microsoft’s new coverage particularly targets MOERA (Microsoft On-line Electronic mail Routing Handle) domains, that are routinely assigned when organizations create new Microsoft 365 tenants. 

These default domains, equivalent to contoso.onmicrosoft.com, have grow to be enticing targets for cybercriminals who exploit newly created tenants to ship spam bursts earlier than detection techniques can intervene.

The throttling mechanism will set off NDR (Non-Supply Report) messages with error code 550 5.7.236 when organizations exceed the 100 exterior recipient restrict throughout the rolling 24-hour window. 

Inside messaging stays unaffected, and the restriction applies solely to exterior recipients after any distribution listing expansions are calculated. 

This technical implementation ensures that official testing and inner communications proceed uninterrupted whereas stopping large-scale spam operations.

The shared status mannequin of onmicrosoft domains has created vital deliverability challenges for official customers. 

As a result of all organizations share variations of the identical area namespace, malicious exercise from one tenant can negatively impression electronic mail deliverability for all different customers on the platform.

Phased Rollout Timeline 

Microsoft has established a structured rollout schedule starting with trial tenants on October 15, 2025, and progressing via totally different group sizes based mostly on Change seat counts. 

The implementation will conclude with tenants having over 10,001 seats by June 1, 2026. Organizations with fewer than three seats will face restrictions beginning December 1, 2025, adopted by progressively bigger organizations via the primary half of 2026.

Technical migration entails a number of important steps together with buying customized domains via approved registrars, configuring DNS validation, and updating main SMTP addresses on all mailboxes. 

Organizations should additionally deal with particular situations the place MOERA domains may be inadvertently used, together with Sender Rewriting Scheme (SRS) configurations, Microsoft Bookings notifications, and numerous Microsoft 365 service integrations.

Directors can analyze present MOERA electronic mail visitors utilizing the Message Hint characteristic in Change Admin Middle with wildcard sender addresses to establish potential impacts earlier than the restrictions take impact. 

Organizations are strongly suggested to start migration planning instantly, because the throttling limits will considerably impression any enterprise operations presently depending on MOERA domains for exterior communications.

Discover this Story Attention-grabbing! Observe us on LinkedIn and X to Get Extra Prompt Updates.

Cyber Security News Tags:Domain, Emails, Limit, Microsoft, Onmicrosoft, Sending, Usage

Post navigation

Previous Post: Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection
Next Post: GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets

Related Posts

OpenSSL Vulnerabilities Let Attackers Execute Malicious Code and Recover Private Key Remotely Cyber Security News
Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack Cyber Security News
Pakistani Actors Built 300+ Cracking Websites Used to Deliver Info-Stealer Malware Cyber Security News
NCSC Urges Organizations to Upgrade Microsoft Windows 11 to Defend Cyberattacks Cyber Security News
Hackers Mimic IT Teams to Exploit Microsoft Teams Request to Gain System Remote Access Cyber Security News
Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark