Microsoft Defender for Office 365 is introducing Mail Bombing Detection to protect against email bombing attacks. This feature will roll out globally from late June to late July 2025, automatically identifying and blocking such attacks. It requires no manual configuration and will be visible in various security tools.
We’re introducing a new detection capability in Microsoft Defender for Office 365 to help protect your organization from a growing threat known as email bombing. This form of abuse floods mailboxes with high volumes of email to obscure important messages or overwhelm systems. The new “Mail Bombing” detection will automatically identify and block these attacks, helping security teams maintain visibility into real threats.
When this will happen:
General Availability (Worldwide): We will begin rolling out in late June 2025 and expect to complete by late July 2025.
How this affects your organization:
Security Operations Analysts and Administrators will see a new detection type labeled Mail Bombing in the following locations:
Messages identified as part of a mail bombing campaign will be automatically sent to the Junk folder. Safe Senders settings will continue to be honored—messages from those senders will not be impacted.
This feature is on by default and requires no manual configuration.
What you can do to prepare:
Compliance considerations: