Skip to content

Office 365 as MX Record

In this tutorial, you will learn how to configure Microsoft Office 365 with Email Security as its MX record.

1. Add Email Security IP addresses to Allow List

  1. Go to the Anti-spam policies page > Select Edit connection filter policy.
  2. In Always allow messages from the following IP addresses or address range, add IP addresses and CIDR blocks mentioned in Egress IPs.
  3. Select Save.
  4. Microsoft recommends disabling SPF Hard fail when an email solution is placed in front of it:
  5. Select Save.

2. Enhanced Filtering configuration

Create an inbound connector

  1. Set up a connector.
  2. Select Partner organization under Connection from.
    • Provide a name for the connector:
      • Name: Email Security Inbound Connector
      • Description: Inbound connector for Enhanced Filtering
  3. In Authenticating sent email, select By verifying that the IP address of the sending server matches one of the following IP addresses, which belongs to your partner organization.
  4. Enter all of the egress IPs in the Egress IPs page.
  5. In Security restrictions, accept the default Reject email messages if they aren't sent over TLS setting.

Enable enhanced filtering

Now that the inbound connector has been configured, you will need to enable the enhanced filtering configuration of the connector.

  1. Go to the Security admin console, and enable enhanced filtering.
  2. Select Automatically detect and skip the last IP address and Apply to entire organization.
  3. Select Save.

Next steps

Now that you have completed the prerequisite steps, you can set up MX/Inline on the Cloudflare dashboard.