Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails

Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails

Posted on August 23, 2025August 23, 2025 By CWS

Microsoft has introduced vital restrictions on electronic mail sending capabilities for organizations utilizing default onmicrosoft.com domains, implementing a throttling system that limits exterior electronic mail supply to 100 recipients per group each 24 hours. 

The coverage change, introduced via the Change Group Weblog, goals to forestall spam abuse whereas encouraging organizations emigrate to customized domains for improved electronic mail deliverability and model illustration.

Key Takeaways1. Microsoft limits onmicrosoft.com domains to 100 exterior emails each day.2. Targets cybercriminals exploiting new tenants, defending shared area status.3. Organizations should buy customized domains, rollout phases via June 2026.

Electronic mail Throttling Imposed

Microsoft’s new coverage particularly targets MOERA (Microsoft On-line Electronic mail Routing Handle) domains, that are routinely assigned when organizations create new Microsoft 365 tenants. 

These default domains, equivalent to contoso.onmicrosoft.com, have grow to be enticing targets for cybercriminals who exploit newly created tenants to ship spam bursts earlier than detection techniques can intervene.

The throttling mechanism will set off NDR (Non-Supply Report) messages with error code 550 5.7.236 when organizations exceed the 100 exterior recipient restrict throughout the rolling 24-hour window. 

Inside messaging stays unaffected, and the restriction applies solely to exterior recipients after any distribution listing expansions are calculated. 

This technical implementation ensures that official testing and inner communications proceed uninterrupted whereas stopping large-scale spam operations.

The shared status mannequin of onmicrosoft domains has created vital deliverability challenges for official customers. 

As a result of all organizations share variations of the identical area namespace, malicious exercise from one tenant can negatively impression electronic mail deliverability for all different customers on the platform.

Phased Rollout Timeline 

Microsoft has established a structured rollout schedule starting with trial tenants on October 15, 2025, and progressing via totally different group sizes based mostly on Change seat counts. 

The implementation will conclude with tenants having over 10,001 seats by June 1, 2026. Organizations with fewer than three seats will face restrictions beginning December 1, 2025, adopted by progressively bigger organizations via the primary half of 2026.

Technical migration entails a number of important steps together with buying customized domains via approved registrars, configuring DNS validation, and updating main SMTP addresses on all mailboxes. 

Organizations should additionally deal with particular situations the place MOERA domains may be inadvertently used, together with Sender Rewriting Scheme (SRS) configurations, Microsoft Bookings notifications, and numerous Microsoft 365 service integrations.

Directors can analyze present MOERA electronic mail visitors utilizing the Message Hint characteristic in Change Admin Middle with wildcard sender addresses to establish potential impacts earlier than the restrictions take impact. 

Organizations are strongly suggested to start migration planning instantly, because the throttling limits will considerably impression any enterprise operations presently depending on MOERA domains for exterior communications.

Discover this Story Attention-grabbing! Observe us on LinkedIn and X to Get Extra Prompt Updates.

Cyber Security News Tags:Domain, Emails, Limit, Microsoft, Onmicrosoft, Sending, Usage

Post navigation

Previous Post: Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection
Next Post: GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets

Related Posts

PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability Cyber Security News
SSH Keys Are Crucial for Secure Remote Access but Often Remain a Blind Spot in Enterprise Security SSH Keys Are Crucial for Secure Remote Access but Often Remain a Blind Spot in Enterprise Security Cyber Security News
Pentest AI Agents Revolutionize Security Testing Pentest AI Agents Revolutionize Security Testing Cyber Security News
New Quantum Route Redirect Tool Lets Attackers Launch One-Click Phishing Attacks on Microsoft 365 Users New Quantum Route Redirect Tool Lets Attackers Launch One-Click Phishing Attacks on Microsoft 365 Users Cyber Security News
SonicWall SMA100 Series N-day Vulnerabilities Technical Details Revealed SonicWall SMA100 Series N-day Vulnerabilities Technical Details Revealed Cyber Security News
Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark