Configure Incoming Filtering with Exchange Online (Microsoft 365)

In order to configure incoming filtering for Exchange Online/Microsoft 365 follow these steps:

  • Step 1 - Add the domain in Spam Experts
  • Step 2 - Create a partner connector and rule in Exchange Online to accept filtered mail
  • Step 3 - Change MX record for the domain to point to incoming servers

Step 1 - Add the domain in Spam Experts

We recommend Adding Domains and Mailboxes via Microsoft 365 sync.

To add the domain manually:

  1. Log in to the Spam Experts control panel as an admin
  2. Click on General > Add Domain
  3. Enter the domain name and click Continue
  4. Under the Destination Routes Hostname enter the destination server IP/hostname, or use the auto-detected route if it is correct

    This may need to be changed as the automatically detected route is detected from the present MX records. Avoid using the filter addresses or any other filtered destination

  5. Click Add routeto add additional route hostnames

    Do not enter multiple hosts for the same destination route e.g. mail.example.invalid and 1.2.3.4 where 1.2.3.4 is the IP address for mail.example.invalid

  6. Select the Regionfrom the dropdown from the following selection
    1. Global (Recommended)

      We strongly recommend using the Global region to provide maximum redundancy

    2. United States
    3. European Union
    4. United Kingdom
    5. Canada
    6. Australia
    7. South Africa
  7. Click Add and go to Overview or Next
    1. Add and go to overview takes you into the Domain Overview
    2. Next provides a summary of the domain configuration, and provides access to the Mailbox Configuration or access to the Domain Overview

Step 2 - Create a partner connector and rule in Exchange Online to accept filtered mail

For further details about creating a partner connector and rule in either the Classic EAC or the New EAC in Microsoft 365, and to ensure you fully read the Microsoft documentation page.

Before beginning, ensure you are a member of the Organization Management role groups in the Microsoft 365 defender portal and Exchange Online.

Step 2:1 - Create the Partner Connector in the Exchange Admin Center

  1. Log in to the Exchange Admin Center with Organization Management admin credentials
  2. Click on Mail Flow > Connectors
  3. Click the + button to add a connector
  4. Choose the following:
    1. Connection FromPartner organization
    2. Connection ToMicrosoft 365
  5. Click Next
  6. Give the connector a Name you will recognize in Step 2:2 #5 and optionally, provide a description
  7. Ensure the What do you want to do after connector is saved setting, Turn it On is selected
  8. Click Next
  9. Choose By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization
    1. Add the following Spam Experts delivery IP ranges one at a time and click the +symbol:
      • 185.201.16.0/24
      • 185.201.17.0/24
      • 185.201.18.0/24
      • 185.201.19.0/24
  10. Click Next
  11. Ensure that Reject email messages if they aren't sent over TLS is ticked and click Next
  12. Verify the settings and click Create Connector
  13. Click Done

Step 2:2 - Create the Rule in the Microsoft 365 Defender Security Portal

  1. Login to the Microsoft 365 defender security portal with Organization Management admin credentials
  2. Under the Email & Collaboration section of the left-hand menu, select Policies & Rules
  3. Click Threat Policies
  4. Scroll to the Rules section and select Enhanced Filtering
  5. Select the Connector Name as created in step 2:1
  6. Select Skip these IP addresses:
    • 185.201.16.0/22
    • 199.115.117.7/32
    • 46.165.223.16/32
    • 94.75.244.176/32
  7. For Apply to these users, select Apply to Entire Organization
  8. Click Save

Failing to setup the partner connector correctly will cause messages to be incorrectly rejected by the Microsoft systems.

Step 3 - Change MX record for the domain to point to incoming servers

Once you have verified configuration as above, update the domain's MX records to route mail through Spam Experts. For full details on MX records (including region specific MX records), see Hosted Cloud MX Records.


Reference Link: https://documentation.n-able.com/spamexperts/userguide/Content/B_Admin%20Level/Microsoft365/conf-inbound-filtering-with-exch-m365.htm#add-domain