Sophos Email: sending limits and bulk sender privileges
Sophos Email limits message and recipient throughput so that a compromised account can’t send spam without restraint. An outbound restriction applies to the account that triggered it, not the entire organization. For demonstrably legitimate bulk mail, an administrator can request reviewed Bulk email sender privileges for a user mailbox.
Quick workflow: record the sending mailbox, recipient count, and sending window; compare the values with the applicable limits; request the privilege under My Products > Email Security > Mailboxes for an ongoing legitimate requirement; and wait for the status. After a rejection, don’t send again immediately—allow the affected window to expire. If the volume isn’t clearly legitimate, stop sending and treat the account as a potential incident.
Prerequisites and security boundary
Before changing capacity, have an active Sophos Email license, a reconciled mailbox inventory, and a reliable forecast of message and recipient counts. For each planned send, record at least the sender mailbox, purpose, frequency, number of messages, number of recipients, and UTC window.
A bulk privilege isn’t a tenant-wide switch or a way to unblock suspicious activity. It is requested per user mailbox, reviewed by Sophos, and can be assigned to no more than 5% of an organization’s users. Don’t submit a request as a workaround for an unexpected volume spike, unknown recipient list, spam, or malware. Follow the incident workflow for account-compromise notifications and response instead.
Read the current limits correctly
The message and recipient counters apply at the same time. A send is too large as soon as either value would exceed its applicable window.
Inbound per recipient
| Source | Limit | Window | When exceeded |
|---|---|---|---|
| one sender | 1,800 messages | one UTC hour | further messages are rejected |
| all senders combined | 3,600 messages | one UTC hour | further messages are rejected |
Both inbound limits apply per recipient. High volume from one sender therefore also counts toward that recipient’s aggregate limit.
Outbound per user mailbox
| Privilege status | Messages in 10 minutes | Recipients in 10 minutes | Messages in 24 hours UTC | Recipients in 24 hours UTC |
|---|---|---|---|---|
| standard user | 400 | 2,000 | 2,000 | 10,000 |
| user with bulk privilege | 3,000 | 15,000 | 30,000 | 150,000 |
A single message can additionally contain no more than 500 recipients. Bulk privilege doesn’t increase this per-message value. A privileged user must split larger lists into controlled sends while remaining below both the 10-minute and 24-hour counters.
Request bulk sender privileges
- In Sophos Fusion (formerly Sophos Central), open My Products > Email Security > Mailboxes.
- Select the eligible user mailbox and choose Request bulk sender privileges.
- Under How often bulk emails are sent?, choose Daily, Weekly, or Monthly.
- Under How many emails are sent per period?, enter the approximate message count for that frequency.
- Under What is the purpose of sending emails in bulk? (eg, invoices to clients), describe the specific business purpose.
- Select Save.
Sophos reviews the request within six hours. A status appears for a request that has already been submitted or granted; another request doesn’t accelerate review. You can later remove the privilege at any time without another review.
If Request bulk sender privileges is missing, open Global Settings > Products and Services > Email. Under Gateway Domains or M365 Mailflow Domains, the mailbox domain must be set to Inbound and Outbound. This direction check only corrects a request prerequisite; don’t redesign mail architecture without change review. See add, import, and manage mailboxes for general manual mailbox administration.
Validate status and sending in a controlled way
Open the mailbox under My Products > Email Security > Mailboxes and check the Bulk email sender privileges section to see whether the request is pending or granted. Only a visibly granted status authorizes the higher limits.
Then send a harmless test to known recipients, comfortably below every applicable limit. Record the sender, UTC start time, message and recipient counts, and result. If successful, increase planned volume in stages while monitoring both the 10-minute and 24-hour budgets. Under Alerts, you can see users who reached their sending limits and change the frequency of user alerts.
Handle rejections and reset windows
When a limit is exceeded, Sophos Email rejects further messages and returns an error to the sender. A recipient counter alone can cause rejection even when the message count appears lower. First correlate the direction, affected mailbox or recipient, UTC time, message count, recipient count, and privilege status.
- Inbound limit: Wait until the affected UTC hour ends, then run a controlled test in the next UTC-hour window.
- Outbound 10-minute limit: Allow the full 10-minute period to expire before a small test send.
- Outbound 24-hour limit: Allow the 24-hour UTC period to expire. Repeated attempts during the block don’t restore sending.
- More than 500 recipients in one message: Review the list and divide it into smaller messages; both cumulative windows still apply.
Don’t use routing, a policy, or an allow list to bypass a limit. If a small test is still rejected after the applicable window, collect timestamps, sender, recipient count, error text, privilege status, and visible alerts, then escalate the case.
Distinguish legitimate load from account abuse
A known campaign with an approved purpose, expected list, and documented owner can be a capacity issue. Unknown recipients, unexpected times, an abrupt pattern change, spam, malware, or a user who denies sending are incident indicators.
In that case, stop queues and scheduled campaigns, disable the account at the responsible identity or mail provider if necessary, reset credentials, and investigate assigned devices. Neither waiting for a rate-limit window nor granting bulk privilege proves that an account is clean. Resume only after documented approval, starting with a small normal test message rather than the accumulated bulk send.