How to get the MS Purview DLP Policy Rule bounce rejection mail as one mail in the same thread

Sarathprasath Krishnaswamy 100 Reputation points
2026-06-12T09:07:33.2833333+00:00

Currently when I have blocked the content in the DLP Policy rule in MS Purview for the MS Exchange location, for as many of my recipients, I get the bounce rejection mail for those many

for eg: If there are 50 recipients in the mail, I get 50 bounce rejection emails, which are blocked because of DLP

If I turn on the "User Notification" in the DLP Rule in MS, it gives a separate email, not threading under the original email, which I cannot use

I want the threading but I want a single bounce rejection mail instead of multiple DLP rejection bounce mail, is there a way to configure it?

Please let us know

Microsoft Security | Microsoft Purview
0 comments No comments

Answer accepted by question author
Pilladi Padma Sai Manisha 11,715 Reputation points Microsoft External Staff Moderator
2026-06-15T08:41:07.65+00:00

Hi Sarath,

What you're seeing is expected behavior and, unfortunately, there isn't a supported way to change it.

For Microsoft Purview DLP policies applied to Exchange Online, when a message is blocked, the resulting rejection/non-delivery notifications are handled by Exchange mail flow processing. If the message has multiple recipients, Exchange can generate separate rejection notifications rather than a single consolidated bounce message.

Enabling User notifications in the DLP rule will send additional informational emails to users, but these notifications are independent of the Exchange-generated rejection messages and won't be threaded under the original email or combined into a single notification.

At this time, there is no configuration option in Microsoft Purview or Exchange Online to generate one threaded DLP rejection email for all recipients.

As an alternative, if your goal is to reduce notification noise, you may consider:

  • Using Policy Tips to warn users before they send the message.

Using User Notifications to provide guidance when a DLP policy is triggered. Using Alert/Incident reports for compliance monitoring instead of relying on rejection emails.

If this functionality is important for your organization, it would require a product enhancement rather than a configuration change.

Additionally, could you confirm the following?

Is the DLP policy scoped only to Exchange Online? Is the action configured as "Block the message" or another enforcement action? Are the emails you're referring to Exchange-generated NDRs, or Purview User Notification emails?

That information would help determine whether there's an opportunity to optimize the user experience within the supported design.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Newest
  1. AI answer

    2026-06-12T09:07:48.3366667+00:00

    This behavior can't be changed with the available DLP configuration options.

    For Exchange DLP rules in Microsoft Purview:

    • User notifications and policy tips can be enabled or disabled per rule, and the notification email text/subject can be customized, but the delivery behavior (one notification per affected item/recipient vs. a single threaded NDR) isn't configurable.
    • Email notifications are sent unprotected and are supported for Exchange, but there is no setting to aggregate or batch them into a single bounce or to force them to appear as part of the same conversation thread as the original message.
    • Email notification batching is only described for unmanaged cloud apps (browser and network) and not for Exchange; that batching is per user and per 10‑minute window, not per original message thread.

    Because of these constraints, a single threaded DLP rejection message replacing multiple individual DLP-related bounces for multiple recipients isn't supported.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.