Are external emails tagged as originating from an external source?
One setting, no licence cost, and it undercuts the most common impersonation technique. Carriers ask because it is close to free and still frequently off.
What the carrier is actually asking
The carrier is asking whether mail arriving from outside the organisation is visibly marked, so that a message claiming to be from the chief executive is obviously external at a glance. It is a small interface change with an outsized effect on impersonation attacks.
Why it is underwritten
Executive impersonation relies on the display name looking familiar. On mobile clients particularly, the display name is often all a user sees. An external tag interrupts that at the moment of reading, before the request is acted on, and it costs nothing to enable.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is directly measurable in Microsoft 365, and it is one of the fastest gaps to close if it is not already on.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Microsoft 365 | External sender identification in Exchange Online | Enabled tenant-wide, which adds the native external tag across clients |
| Microsoft 365 | MailTips configuration | Enabled, so users are warned when replying to external recipients as well as when receiving from them |
| Microsoft 365 | Any transport rule adding a banner, and its exclusions | Where a custom banner is used, its exclusion list is reviewed, since partner exclusions accumulate |
| Microsoft 365 | Anti-phishing impersonation protection, first-contact safety tip | Enabled, which flags messages from senders the recipient has never corresponded with |
| Microsoft 365 | Behaviour on mobile and web clients | The tag appears where users actually read mail, since a banner that only renders on desktop misses the highest-risk context |
Transport rules that add a banner usually accumulate exclusions for partners and vendors whose mail looked untidy with it. Those excluded domains are exactly the ones an attacker will impersonate, because their mail arrives looking internal.
What a defensible yes requires
- External tagging is enabled tenant-wide with minimal exclusions.
- The tag renders on mobile and web, not only on the desktop client.
- First-contact safety tips are enabled for senders never seen before.
- MailTips warn on outbound external replies as well.
- Any exclusion list is reviewed rather than accumulated.
How this answer goes wrong
A transport rule adds a banner and a dozen partner domains are excluded, so the most trusted external senders arrive unmarked. Or the banner is HTML that renders inconsistently on mobile, where most impersonation is read. The setting reports as enabled and the effect is partial.
Frequently asked
Do users stop noticing the tag?
Somewhat, over time. It still works at the moment that matters, when the message asks for something unusual, and its cost is close to zero.
Native tagging or a custom banner?
Native, where available. It renders consistently across clients and needs no maintenance, whereas custom rules drift and collect exclusions.
What about first-contact tips?
Worth enabling alongside. A sender you have never corresponded with is a meaningfully different signal from a sender outside the organisation.
Does this help with internal compromise?
No. Mail from a compromised internal mailbox is genuinely internal. That is why the impersonation protections and reporting controls matter alongside it.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture