Overwhelmed by onmicrosoft.com SPAM EMAILS

Anonymous
2023-05-29T18:58:59+00:00

How do I block onmicrosoft.com SPAM EMAILS? I am getting relentlessly spammed and cannot seem to block these emails. This is a serious problem because about every third or forth email is this onmicrosoft.com SPAM EMAIL. I like office 365 but this is ridiculous!!!

Microsoft 365 and Office | Subscription, account, billing | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

62 answers

Sort by: Newest
  1. Anonymous
    2024-01-30T16:34:42+00:00

    Yes, Steven42, "The obvious solution is to block all emails coming from an "onmicrosoft.com". My issue is that I HAVE blocked any emails with "onmicrosoft.com" in the sender address, AND IT DOESN'T WORK! I believe Microsoft has nullified rules pertaining to "onmicrosoft.com". Those damn emails CAN'T be blocked using their Outlook email program (OWA). The spammers use it because it says Microsoft in the address, which give it legitimacy. They PAY Microsoft for that privilege, and it bypasses rules and goes thru to annoy those who use a FREE email system. If this isn't criminal, it at least sure isn't ethical.

    I also think you are correct that Microsoft doesn't care and has no plans or incentive to fix the issue.

    I'm thinking of dumping OWA for Gmail. At least their filters work.

    Microsoft, are you listening?????

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-01-30T14:22:04+00:00

    I've just been sending the headers of each and every one that doesn't get filtered by [0-9].onmicrosoft.com to cdoccm@microsoft.com and report_******@outlook.com. It was 38 yesterday. Before I put that refuse connection rule in, I was doing 110+/day. It's crazy that MS hasn't gotten a handle on their problem with as many samples as we've all sent in.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-01-30T13:49:57+00:00

    First off, I'll say that I have two Microsoft accounts, a web-version provided through work, and a personal paid subscription as well.

    In my personal email account, that is not Google and on a secure server, I do not receive any spam mail here, with the exception of spam mails all originating from "onmicrosoft.com"

    This is clearly a microsoft issue, and they clearly have no intention of resolving it. Their feelings about their products, services, and customers is also quite clear. They don't care.

    The obvious solution is to block all emails coming from an "onmicrosoft.com" account. You may miss some legitimate emails, but as another user stated, this will just be an opportunity to explain to someone what the problem is. Eventually microsoft will lose all users to this platform, and maybe then they'll start to care.

    On another note, I had filed a BBB complaint against them for another issue. This went around tech support for a month or so. From this experience, I can tell you with absolute confidence that they do not care about their customers.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-01-22T10:24:52+00:00

    the same issue spam from onmicrosoft everyday, of course can do some rule to block but, should take action from ms to clear out such spam account.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-01-16T18:21:21+00:00

    Thanks, this is very helpful. So I only needed to create 10 spam rules in my email client for the 10 digits in:

    "digit".onmicrosoft.com.

    and that did the trick.

    I've decided to script a temporary transport rule that junks/ quarantines everything ending on "number".onmicrosoft.com using regex expressions.

    It seems as if the generated onmicrosoft.com accounts always have a number as last character.

    (credits go to Knox203 in this article --> Spam increase from onmicrosoft.com addresses : r/msp (reddit.com) )

    However,

    Trying to execute this script using the Secure Application Model, it seems as if I have insufficient rights to create transport rules.

    I can't find a definitive answer if this is an application permission problem, or that this is by design. I can however if i use interactive signin, without the delegated application permissions.

    Any thoughts on this?

    We have loads of customers complaining about this rn. Logging into 400 tenants isn't an option unfortunately ;-)

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments