Products & Markets

Microsoft Defender for Office 365 Adds Default Email Bombing Protection

Microsoft has announced that all Defender for Office 365 customers will receive automatic protection against email bombing attacks by the end of July 2025. The new security feature will be enabled by default across all customer environments.

Email bombing involves flooding target email addresses with thousands of messages, often used by attackers to overwhelm users or hide critical security alerts within the message volume. The attacks can disrupt normal email operations and serve as cover for social engineering attempts.

The new protection system automatically detects abnormal incoming mail volumes by analyzing historical sender patterns and spam indicators. When email bombing is detected, the system redirects the flood of messages to the Outlook Junk folder rather than the primary inbox.

Microsoft’s implementation maintains existing safe sender lists, ensuring that legitimate high-volume communications from trusted sources continue to reach recipients normally. System administrators will receive alerts when email bombing incidents are detected and gain access to analysis tools for investigating the attacks.

The cloud-based filtering system operates automatically without requiring configuration changes from administrators. Microsoft positions the feature as protection against both the direct impact of spam floods and the secondary social engineering attacks that often accompany email bombing campaigns.

The timing of this security enhancement comes amid recent email infrastructure challenges, including the July 9-10 global Outlook outage that affected email access for thousands of users worldwide. While that incident resulted from configuration issues rather than malicious attacks, it highlighted the importance of email system resilience and the potential impact of email disruptions on business operations.

The email bombing protection joins Microsoft’s existing suite of email security features in Defender for Office 365, which already includes anti-phishing, safe attachments, and advanced threat protection capabilities. The feature will be automatically deployed to all customer environments without requiring opt-in or additional licensing.

Related coverage

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory