A recent influx of spam mail from various OnMicrosoft domains (<random letters>.onmicrosoft.com) have begun reaching my users. To attempt to block this, I created an Email Restriction to block incoming mail from the domain onmicrosoft.com (Understanding that I was going to lose any legitimate mail from this domain). However, this filter blocks none of the email as this domain uses subdomains which are given out to individual accounts.
This restriction is enabled for our policy- the only policy in place for all our users.
This restriction is not blocking mail properly. We have received mail from, as an example, 6sr1v6x.onmicrosoft.com TODAY that is bypassing this filter.
The issue is that this filter does not accept subdomain wildcards.
I cannot create a filter that blocks *.onmicrosoft.com as a domain option.
Because of this, spammers can automatically generate new OnMicrosoft instances faster than I can manually block them. Email that will come in this way will still reach my users before it can be blocked on future sends. I am ultimately playing a cat-and-mouse game where I will always be behind the spammers.
How can I use the Email Restrictions setting to universally block all *.onmicrosoft.com addresses from sending mail to my users?