5 - Junk email folder and administrative quarantine
In this tutorial, you will learn to deliver BULK messages to the user's junk email folder, and MALICIOUS, SPAM, and SPOOF messages to the Administrative Quarantine (this requires an administrator to release the emails).
To configure anti-spam policies:
- 
Open the Microsoft 365 Defender console ↗. 
- 
Go to Email & collaboration > Policies & rules. 
- 
Select Threat policies. 
- 
Under Policies, select Anti-spam. 
- 
Select the Anti-spam inbound policy (Default) text (not the checkbox). 
- 
In Actions, scroll down and select Edit actions. 
- 
Set the following conditions and actions (you might need to scroll up or down to find them): 
- Spam: Move messages to Junk Email folder.
- High confidence spam: Quarantine message.
- Select quarantine policy: _AdminOnlyAccessPolicy_.
 
- Phishing: Quarantine message.
- Select quarantine policy: _AdminOnlyAccessPolicy_.
 
- High confidence phishing: Quarantine message.
- Select quarantine policy: _AdminOnlyAccessPolicy_.
 
- Retain spam in quarantine for this many days: Default is 15 days. Email Security recommends 15-30 days.
- Select the spam actions in the above step.
 
- Select Save.
To create the transport rules that will send emails with certain disposition to Email Security:
- 
Open the new Exchange admin center ↗. 
- 
Go to Mail flow > Rules. 
- 
Select Add a Rule > Create a new rule. 
- 
Set the following rule conditions: - Name: Email Security Deliver to Junk Email folder`.
- Apply this rule if: The message headers > includes any of these words.
- Enter text: X-CFEmailSecurity-Disposition> Save.
- Enter words: BULK> Add > Save.
 
- Enter text: 
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following - _Modify the message properties_ > _Set the Spam Confidence Level (SCL)_ > _5_.
 
- 
Select Next. 
- 
You can use the default values on this screen. Select Next. 
- 
Review your settings and select Finish > Done. 
- 
Select the rule Email Security Deliver to Junk Email folder` you have just created, and Enable. 
- 
Select Add a Rule > Create a new rule. 
- 
Set the following rule conditions: - Name: `Email Security Admin Managed Host Quarantine`.
- Apply this rule if: The message headers > includes any of these words.
- Enter text: X-CFEmailSecurity-Disposition> Save.
- Enter words: `MALICIOUS`, `UCE`, `SPOOF` > Add > Save.
 
- Enter text: 
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following: _Redirect the message to_ > _hosted quarantine_.
 
- 
Select Next. 
- 
You can use the default values on this screen. Select Next. 
- 
Review your settings and select Finish > Done. 
- 
Select the rule `Email Security Admin Managed Host Quarantine` you have just created, and select Enable. 
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Directory
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark