---
title: Scripts for Safelisting in Microsoft 365
description: This article provides two safelisting scripts for Microsoft 365 email clients.
---

[Skip to content](https://support.hooksecurity.co/scripts-for-safelisting-in-microsoft-365#main-content)

English

Show submenu for translations

[Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new?hsLang=en) [Customer Portal](https://support.hooksecurity.co/tickets-view?hsLang=en)

[![Hook\_Logo (3)](https://support.hooksecurity.co/hs-fs/hubfs/Hook_Logo%20(3).png?width=150&height=113&name=Hook_Logo%20(3).png)](https://www.hooksecurity.co/welcome)

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)

Open main navigation

Close main navigation

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)
- English
  
  Show submenu for translations
- [Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new)
- [Customer Portal](https://support.hooksecurity.co/tickets-view)
- [Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

[Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.hooksecurity.co/?hsLang=en)
2. [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en)
3. [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)

# Scripts for Safelisting in Microsoft 365

## This article provides two safelisting scripts for Microsoft 365 email clients.

This article provides two safelisting scripts for Microsoft 365 email clients. Learn more about PowerShell scripting in [Exchange Online docs](https://docs.microsoft.com/en-us/powershell/exchange/exchange-online-powershell?view=exchange-ps) and [Azure Active directory docs](https://docs.microsoft.com/en-us/powershell/azure/active-directory/install-adv2?view=azureadps-2.0). 

1. Safe Senders
2. Add an IP and Domain Policy
3. Add a URL Policy
4. Edit a Rule
5. Remove policy
6. Mail Flow Rules (deprecated)

#### Safe Senders

Adding senders to a user's safe senders list will remove the "Some content of this message has been blocked..." banner and allow the mail client to automatically download images in emails from the sender. If images are downloaded, opens will be recorded when a user views the email.

```
if (-NOT (Get-Module -ListAvailable -Name ExchangeOnlineManagement)) {Install-Module -Name ExchangeOnlineManagement}Import-Module ExchangeOnlineManagement$admin = Read-Host "Exchange admin email or UPN"Connect-ExchangeOnline -UserPrincipalName $admin$users = Get-User$senders = 'example@example.com' #add safe senders here, in quotes and comma-separatedforeach($user in $users){$out = 'Adding Trusted Senders to {0}' -f $user.UserPrincipalNameWrite-Output $outSet-MailboxJunkEmailConfiguration $user.UserPrincipalName -TrustedSendersAndDomains @{Add=$senders}}Write-Output "Finished!"
```

> NOTE: You will need to assign all senders you wish to add to user's safe senders list to the $senders variable, in quotes and comma-separated. For example $senders = 'example@asd.com', 'second@123.com' , ...

#### Add an IP and Domain Policy

Use the following script if you have not set up a phishing simulation policy.

```
if (-NOT (Get-Module -ListAvailable -Name ExchangeOnlineManagement)) {    Install-Module -Name ExchangeOnlineManagement}Import-Module ExchangeOnlineManagement$admin = Read-Host "Exchange admin email or UPN"Connect-IPPSSession -UserPrincipalName $admin#input phishing domains below, separated by commas and quoted (20 domain maximum). E.g. "$domains = 'example.com','example2.com','example3.com', ..."$domains = ''New-PhishSimOverridePolicy -Name PhishSimOverridePolicyNew-PhishSimOverrideRule -Name PhishSimOverrideRule -Policy PhishSimOverridePolicy -Domains $domains -SenderIpRanges 64.191.166.196
```

#### Add a URL Policy

Use the following script if you have not set up a phishing simulation policy.

```
if (-NOT (Get-Module -ListAvailable -Name ExchangeOnlineManagement)) {    Install-Module -Name ExchangeOnlineManagement}#input phishing domain URLs below, separated by commas and quoted (20 domain maximum). #The URLs must have a leading *. and trailing /* E.g. "$urls = '*.example.com/*','*.example2.com/*','*.example3.com/*', ..."$urls = ''Import-Module ExchangeOnlineManagement$admin = Read-Host "Exchange admin email or UPN"Connect-ExchangeOnline -UserPrincipalName $adminGet-TenantAllowBlockListItems -ListType Url -ListSubType AdvancedDeliveryNew-TenantAllowBlockListItems -Allow -ListType Url -ListSubType AdvancedDelivery -Entries $urls -NoExpiration
```

#### Edit a Rule

Use the following script if your tenant has existing phishing simulation rules.

```
if (-NOT (Get-Module -ListAvailable -Name ExchangeOnlineManagement)) {    Install-Module -Name ExchangeOnlineManagement}Import-Module ExchangeOnlineManagement$admin = Read-Host "Exchange admin email or UPN"Connect-IPPSSession -UserPrincipalName $admin#input phishing domains below, separated by commas and quoted (20 domain maximum). E.g. "$domains = 'example.com','example2.com','example3.com', ..."$domains = ''$rule = Get-PhishSimOverrideRuleSet-PhishSimOverrideRule -Identity $rule.Name -RemoveSenderIpRanges $rule.SenderIpRanges -RemoveDomains $rule.Domains -AddDomains $domains -AddSenderIpRanges 64.191.166.196Get-PhishSimOverrideRule
```

#### Remove policy

If you wish to remove a phishing simulation policy, use the script below.

```
if (-NOT (Get-Module -ListAvailable -Name ExchangeOnlineManagement)) {    Install-Module -Name ExchangeOnlineManagement}Import-Module ExchangeOnlineManagement$admin = Read-Host "Exchange admin email or UPN"Connect-IPPSSession -UserPrincipalName $adminRemove-PhishSimOverridePolicy -Identity PhishSimOverridePolicy
```

#### Mail Flow Rules (deprecated)

Implement the four mail flow rules for bypassing by Junk, Spam and Clutter by IP and email Header 

```
if (-NOT (Get-Module -ListAvailable -Name ExchangeOnlineManagement)) {Install-Module -Name ExchangeOnlineManagement}Import-Module ExchangeOnlineManagement$UserPrincipalName = Read-Host "UserPrincipalName"$HeaderValue = Read-Host "X-PHISHTEST Header Value (default PhishingBox)"if ([string]::IsNullOrEmpty($HeaderValue)) {$HeaderValue = "PhishingBox"}Connect-ExchangeOnline -UserPrincipalName $UserPrincipalNameNew-TransportRule "Phishing Testing - Bypass Spam By IP" -SenderIpRanges "64.191.166.0/24" -SetHeaderName "X-MS-Exchange-Organization-BypassClutter" -SetHeaderValue "true" -SetSCL "-1"New-TransportRule "Phishing Testing - Bypass Junk By IP" -SenderIpRanges "64.191.166.0/24" -SetHeaderName "X-Forefront-Antispam-Report" -SetHeaderValue "SFV:SKI;"New-TransportRule "Phishing Testing - Bypass Spam By Header" -HeaderContainsMessageHeader "X-PHISHTEST" -HeaderContainsWords $HeaderValue -SetHeaderName "X-MS-Exchange-Organization-BypassClutter" -SetHeaderValue "true" -SetSCL "-1"New-TransportRule "Phishing Testing - Bypass Junk By Header" -HeaderContainsMessageHeader "X-PHISHTEST" -HeaderContainsWords $HeaderValue -SetHeaderName "X-Forefront-Antispam-Report" -SetHeaderValue "SFV:SKI;"
```

 

- [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en#main-content)

    - [General](https://support.hooksecurity.co/getting-started?hsLang=en#general)
    - [General Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#general-safelisting)
    - [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)
    - [GSuite Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#gsuite-safelisting)
    - [Firewall/Spam Filter Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#firewall-spam-filter-safelisting)
    - [Creating Groups/Adding Targets](https://support.hooksecurity.co/getting-started?hsLang=en#creating-groups-adding-targets)
    - [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)
    - [3rd Party Integrations](https://support.hooksecurity.co/getting-started?hsLang=en#3rd-party-integrations)
    - [Platform Settings](https://support.hooksecurity.co/getting-started?hsLang=en#platform-settings)
- [Hook Academy](https://support.hooksecurity.co/hook-academy?hsLang=en#main-content)

    - [Campaign Ideas](https://support.hooksecurity.co/hook-academy?hsLang=en#campaign-ideas)
    - [Industry Specific Campaigns](https://support.hooksecurity.co/hook-academy?hsLang=en#industry-specific-campaigns)
    - [Course Reviews](https://support.hooksecurity.co/hook-academy?hsLang=en#course-reviews)
    - [Mastering Reporting](https://support.hooksecurity.co/hook-academy?hsLang=en#mastering-reporting)
    - [Becoming Compliant](https://support.hooksecurity.co/hook-academy?hsLang=en#becoming-compliant)
    - [Suggest a Hook Academy Topic](https://support.hooksecurity.co/hook-academy?hsLang=en#suggest-a-hook-academy-topic)
- [Tests/Campaigns](https://support.hooksecurity.co/tests-campaigns?hsLang=en#main-content)

    - [Reseller Only](https://support.hooksecurity.co/tests-campaigns?hsLang=en#reseller-only)
- [School](https://support.hooksecurity.co/school?hsLang=en#main-content)

    - [3rd Party Integrations](https://support.hooksecurity.co/school?hsLang=en#3rd-party-integrations)
    - [Troubleshooting](https://support.hooksecurity.co/school?hsLang=en#troubleshooting)
    - [Branding](https://support.hooksecurity.co/school?hsLang=en#branding)
    - [Course](https://support.hooksecurity.co/school?hsLang=en#course)
    - [Students](https://support.hooksecurity.co/school?hsLang=en#students)
    - [Automations](https://support.hooksecurity.co/school?hsLang=en#automations)
- [Reports](https://support.hooksecurity.co/reports?hsLang=en#main-content)

    - [Generate Reports](https://support.hooksecurity.co/reports?hsLang=en#generate-reports)
- [FAQs](https://support.hooksecurity.co/faqs?hsLang=en#main-content)

    - [Troubleshooting](https://support.hooksecurity.co/faqs?hsLang=en#troubleshooting)
    - [Campaign of the Month](https://support.hooksecurity.co/faqs?hsLang=en#campaign-of-the-month)
- [Reseller Guide](https://support.hooksecurity.co/reseller-guide?hsLang=en)
- [Hook Security Updates](https://support.hooksecurity.co/hook-security-updates?hsLang=en)
- [Onboarding Guides](https://support.hooksecurity.co/onboarding-guides?hsLang=en)
- [Managed Services](https://support.hooksecurity.co/managed-services?hsLang=en)

- [Default HubSpot Blog](https://hooksecurity-6535385.hs-sites.com/blog)

[![Newsletter\_Logo-08](https://support.hooksecurity.co/hs-fs/hubfs/Newsletter_Logo-08.png?width=250&height=59&name=Newsletter_Logo-08.png "Newsletter_Logo-08")](http://hooksecurity.co)

Proudly Headquartered in Lakeland, Floirda

<https://www.linkedin.com/company/hooksecurity>

Copyright © 2026, Hook Security Inc.