Proofpoint Office 365 Configuration
Proofpoint Set Up Purchase
Purchase Proofpoint Essentials set up support and get your Office 365 configuration completed with our team.
Office 365 Configuration
Before You Start
Before continuing, you should have the following information readily available:
- the MX records for the domains you are configuring (needed for configuring Proofpoint Essentials)
- your Proofpoint Essentials IPs, Smart Host and SPF (needed for configuring Microsoft 365)
- a Microsoft 365 administrator account (needed for configuring Microsoft 365)
In addition, be sure the following steps have been completed:
- spam and digest settings have been configured
- filter policies and/or sender lists have been set up
- all users have been added to the organization
- all email relays have been added to the organization and have been verified
Set Up Inbound Mail flow
Proofpoint Essentials is deployed between the Microsoft 365 environment and the internet. Inbound mail is routed to Proofpoint Essentials by changing the MX records. After email has been processed by Proofpoint Essentials, it is routed to Office 365.
You may have already completed the following step. If so, please proceed to the next step, Update the domain(s) associated With your Proofpoint Essentials account.
Configure Proofpoint Essentials for Inbound Mail Flow
Locate your MX record for the domain
- Sign In to the Microsoft 365 Admin center.
- Click Settings, then Domains.
- Click on the domain you want to manage, then click on the DNS records tab.
- Under Microsoft Exchange, locate the MX row in the table.
- Copy the Value (e.g. bobsbooksupplies-com.mail.protection.outlook.com) shown in the Value column of the MX row.
You may have already completed the following step. If so, please proceed to the next step, Configure Microsoft 365.
Update the domain(s) associated With your Proofpoint Essentials account
- While logged into Proofpoint Essentials, under Account Management, click Domains.
- Click the (menu) next to the domain you wish to edit and click Edit Domain.
- Ensure the Domain Type is set to Relay. (If it is set to Management, change it.)
- In the Primary Delivery Destination field, paste the primary delivery destination that you copied from the Microsoft Exchange MX Value field earlier (e.g. bobsbooksupplies.com.mail.protection.outlook.com).
- Click Save.
- If editing more than one domain, repeat the procedure for each domain.
Configure Microsoft 365
By-Pass Spam Filtering in Microsoft 365
- Sign In to the Microsoft 365 Admin center.
- Under Admin Centers, click Exchange. This launches the Exchange Admin Center.
- Click Mail flow, then Rules.
- Click Add a rule and, from the menu, select Create a new rule.
- Enter a name for the rule (e.g. "Bypass Spam Filtering for Proofpoint Essentials").
- In the "Apply this rule if" menu, select The sender, then IP address is in any of these ranges or exactly matches.
- Add each IP address to the IP address text field, clicking Add after each entry.
- 208.56.1.0/25
- 67.231.152.0/24
- 67.231.153.0/24
- 67.231.154.0/24
- 67.231.155.0/24
- 67.231.156.0/24
- 67.231.144.0/24
- 67.231.145.0/24
- 67.231.146.0/24
- 67.231.147.0/24
- 67.231.148.0/24
- 67.231.149.0/24
- 148.163.128.0/19
- Click Save.
- From the Do the following menu, select Modify the message properties, then set the spam confidence level (SCL) and select Bypass spam filtering.
For organizations using Proofpoint Essentials URL Defense, Microsoft 365's Advanced Email Threat protection (Safelink rewrites) need to be disabled, as the two technologies are not compatible. To do this:
- Click the + (add) icon next to the Modify the message properties entry you just edited. This adds a row.
- From the And menu, select Modify the message properties, then set a message header.
- Click Enter text (next to message header), then enter X-MS-Exchange-Organization-SkipSafeLinksProcessing in the message header field.
- Click Save.
- Click Enter text next to "value" and enter 1 in the message header field.
- Click Save.
- Click Next.
- Select Enforce, then click Next.
- Review the information, then click Finish.
The transport rule this process creates is enabled by default. You can leave the rule enabled, since it only applies to mail that will be received by Proofpoint Essentials.
Create Inbound Connector
An inbound connector is used to manage mail traffic between Microsoft 365 and Proofpoint Essentials.
- In the Exchange Admin Center, click Mail flow, then Connectors.
- Click Add a connector.
- For "Connection from", select Partner organization.
- Connection to is automatically set to Office 365.
- Click Next and enter a name for the connector (e.g. Proofpoint Essentials Inbound Connector).
- Optionally, enter a description (e.g. Inbound connector for Proofpoint Essentials).
- Clear the Turn it on checkbox: the inbound connector should be turned on when mailflow is cutover.
- Click Next.
- Select By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization.
- Add each IP address to the IP address text field, clicking (add) after each IP address entered. IP addresses are located on the Connection Details page (IP Addresses column).
- Click Next.
- Ensure Reject email messages if they aren't over TLS is checked.
- Click Next.
- Review the information, then click Create connector.
- Click Done.
Proofpoint recommends that Microsoft 365 be configured to accept mail only from Proofpoint IPs. If this is not done, it is possible for senders to route directly to your mail system instead of following normal MX lookups to route through Proofpoint Essentials.
Set Up Outbound Mail flow
Proofpoint Essentials is deployed between the Microsoft 365 environment and the internet. Outbound mail is routed to Proofpoint Essentials by configuring an outbound mail gateway. If you do not want to route outbound email through Proofpoint Essentials, you can skip this step. However, this step is required if the Email Encryption or Email Warning Tag features are being used.
Configure Proofpoint Essentials for Outbound Mail Flow
- Under Account Management, click Features.
- Check Enable Outbound Relaying.
- Click Save.
- Under Account Management, click Domains.
- Under Sending Servers, click Manage Hosted Services.
- Click the (enable) control next to Office 365, then click Save.
Create Outbound Connector
An outbound connector is used to manage outbound traffic between Microsoft 365 and Proofpoint Essentials.
- Sign In to the Microsoft 365 Admin center.
- Under Admin centers, click Exchange. This launches the Exchange Admin Center.
- Click Mail Flow, then Connectors.
- Click Add a connector.
- For "Connection from", select Office 365.
- For "Connection to", select Partner organization.
- Click Next.
- Enter a name for the connector (e.g. Proofpoint Essentials Outbound Connector).
- Optionally, enter a description (e.g. Outbound connector for Proofpoint Essentials).
- Clear the Turn it on checkbox.
- The outbound connector should be turned on when mailflow will be cutover.
- Click Next.
- Select Only when email messages are sent to these domains.
- Enter * (asterisk) to the domain text field, then click (add). The asterisk indicates all domains.
- Click Next.
- Select Route email through these smart hosts.
- Locate the smarthost value (e.g. outbound-us1.ppe-hosted.com) on the Connection Details page (Smarthost column). Add it to the text field, then click (add).
- Click Next.
- Ensure both Always use Transport Layer Security (TLS) to secure the connection (recommended) and Issued by a trusted certificate authority (CA) are checked.
- Click Next.
- Enter an email address that can be used for validation. This can be any email other than one for your own domain.
- Click Validate. Note that even if the validation fails, you can proceed.
- Click Save.
Paid Set Up Support
Prefer to have our team handle the configuration? We can complete the Proofpoint Essentials setup for you, including the MX record, SPF, connector, and routing steps on this page.
Request a call back or call (213) 545-0601 to book paid set up support.
