Iron Cove Solutions Logo
  • MIGRATION

Proofpoint Office 365 Configuration

Proofpoint Set Up Purchase

Purchase Proofpoint Essentials set up support and get your Office 365 configuration completed with our team.

Office 365 Configuration

Before You Start

Before continuing, you should have the following information readily available:

  • the MX records for the domains you are configuring (needed for configuring Proofpoint Essentials)
  • your Proofpoint Essentials IPs, Smart Host and SPF (needed for configuring Microsoft 365)
  • a Microsoft 365 administrator account (needed for configuring Microsoft 365)

In addition, be sure the following steps have been completed:

  • spam and digest settings have been configured
  • filter policies and/or sender lists have been set up
  • all users have been added to the organization
  • all email relays have been added to the organization and have been verified

Set Up Inbound Mail flow

Proofpoint Essentials is deployed between the Microsoft 365 environment and the internet. Inbound mail is routed to Proofpoint Essentials by changing the MX records. After email has been processed by Proofpoint Essentials, it is routed to Office 365.

You may have already completed the following step. If so, please proceed to the next step, Update the domain(s) associated With your Proofpoint Essentials account.

Configure Proofpoint Essentials for Inbound Mail Flow

Locate your MX record for the domain

  1. Sign In to the Microsoft 365 Admin center.
  2. Click Settings, then Domains.
  3. Click on the domain you want to manage, then click on the DNS records tab.
  4. Under Microsoft Exchange, locate the MX row in the table.
  5. Copy the Value (e.g. bobsbooksupplies-com.mail.protection.outlook.com) shown in the Value column of the MX row.

You may have already completed the following step. If so, please proceed to the next step, Configure Microsoft 365.

Update the domain(s) associated With your Proofpoint Essentials account

  1. While logged into Proofpoint Essentials, under Account Management, click Domains.
  2. Click the (menu) next to the domain you wish to edit and click Edit Domain.
  3. Ensure the Domain Type is set to Relay. (If it is set to Management, change it.)
  4. In the Primary Delivery Destination field, paste the primary delivery destination that you copied from the Microsoft Exchange MX Value field earlier (e.g. bobsbooksupplies.com.mail.protection.outlook.com).
  5. Click Save.
  6. If editing more than one domain, repeat the procedure for each domain.

Configure Microsoft 365

By-Pass Spam Filtering in Microsoft 365

  1. Sign In to the Microsoft 365 Admin center.
  2. Under Admin Centers, click Exchange. This launches the Exchange Admin Center.
  3. Click Mail flow, then Rules.
  4. Click Add a rule and, from the menu, select Create a new rule.
  5. Enter a name for the rule (e.g. "Bypass Spam Filtering for Proofpoint Essentials").
  6. In the "Apply this rule if" menu, select The sender, then IP address is in any of these ranges or exactly matches.
  7. Add each IP address to the IP address text field, clicking Add after each entry.
  • 208.56.1.0/25
  • 67.231.152.0/24
  • 67.231.153.0/24
  • 67.231.154.0/24
  • 67.231.155.0/24
  • 67.231.156.0/24
  • 67.231.144.0/24
  • 67.231.145.0/24
  • 67.231.146.0/24
  • 67.231.147.0/24
  • 67.231.148.0/24
  • 67.231.149.0/24
  • 148.163.128.0/19
  1. Click Save.
  2. From the Do the following menu, select Modify the message properties, then set the spam confidence level (SCL) and select Bypass spam filtering.

For organizations using Proofpoint Essentials URL Defense, Microsoft 365's Advanced Email Threat protection (Safelink rewrites) need to be disabled, as the two technologies are not compatible. To do this:

  1. Click the + (add) icon next to the Modify the message properties entry you just edited. This adds a row.
  2. From the And menu, select Modify the message properties, then set a message header.
  3. Click Enter text (next to message header), then enter X-MS-Exchange-Organization-SkipSafeLinksProcessing in the message header field.
  4. Click Save.
  5. Click Enter text next to "value" and enter 1 in the message header field.
  6. Click Save.
  7. Click Next.
  8. Select Enforce, then click Next.
  9. Review the information, then click Finish.

The transport rule this process creates is enabled by default. You can leave the rule enabled, since it only applies to mail that will be received by Proofpoint Essentials.

Create Inbound Connector

An inbound connector is used to manage mail traffic between Microsoft 365 and Proofpoint Essentials.

  1. In the Exchange Admin Center, click Mail flow, then Connectors.
  2. Click Add a connector.
  3. For "Connection from", select Partner organization.
  4. Connection to is automatically set to Office 365.
  5. Click Next and enter a name for the connector (e.g. Proofpoint Essentials Inbound Connector).
  6. Optionally, enter a description (e.g. Inbound connector for Proofpoint Essentials).
  7. Clear the Turn it on checkbox: the inbound connector should be turned on when mailflow is cutover.
  8. Click Next.
  9. Select By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization.
  10. Add each IP address to the IP address text field, clicking (add) after each IP address entered. IP addresses are located on the Connection Details page (IP Addresses column).
  11. Click Next.
  12. Ensure Reject email messages if they aren't over TLS is checked.
  13. Click Next.
  14. Review the information, then click Create connector.
  15. Click Done.

Proofpoint recommends that Microsoft 365 be configured to accept mail only from Proofpoint IPs. If this is not done, it is possible for senders to route directly to your mail system instead of following normal MX lookups to route through Proofpoint Essentials.

Set Up Outbound Mail flow

Proofpoint Essentials is deployed between the Microsoft 365 environment and the internet. Outbound mail is routed to Proofpoint Essentials by configuring an outbound mail gateway. If you do not want to route outbound email through Proofpoint Essentials, you can skip this step. However, this step is required if the Email Encryption or Email Warning Tag features are being used.

Configure Proofpoint Essentials for Outbound Mail Flow

  1. Under Account Management, click Features.
  2. Check Enable Outbound Relaying.
  3. Click Save.
  4. Under Account Management, click Domains.
  5. Under Sending Servers, click Manage Hosted Services.
  6. Click the (enable) control next to Office 365, then click Save.

Create Outbound Connector

An outbound connector is used to manage outbound traffic between Microsoft 365 and Proofpoint Essentials.

  1. Sign In to the Microsoft 365 Admin center.
  2. Under Admin centers, click Exchange. This launches the Exchange Admin Center.
  3. Click Mail Flow, then Connectors.
  4. Click Add a connector.
  5. For "Connection from", select Office 365.
  6. For "Connection to", select Partner organization.
  7. Click Next.
  8. Enter a name for the connector (e.g. Proofpoint Essentials Outbound Connector).
  9. Optionally, enter a description (e.g. Outbound connector for Proofpoint Essentials).
  10. Clear the Turn it on checkbox.
  11. The outbound connector should be turned on when mailflow will be cutover.
  12. Click Next.
  13. Select Only when email messages are sent to these domains.
  14. Enter * (asterisk) to the domain text field, then click (add). The asterisk indicates all domains.
  15. Click Next.
  16. Select Route email through these smart hosts.
  17. Locate the smarthost value (e.g. outbound-us1.ppe-hosted.com) on the Connection Details page (Smarthost column). Add it to the text field, then click (add).
  18. Click Next.
  19. Ensure both Always use Transport Layer Security (TLS) to secure the connection (recommended) and Issued by a trusted certificate authority (CA) are checked.
  20. Click Next.
  21. Enter an email address that can be used for validation. This can be any email other than one for your own domain.
  22. Click Validate. Note that even if the validation fails, you can proceed.
  23. Click Save.

Paid Set Up Support

Prefer to have our team handle the configuration? We can complete the Proofpoint Essentials setup for you, including the MX record, SPF, connector, and routing steps on this page.

Request a call back or call (213) 545-0601 to book paid set up support.

Buy Paid Set UpCall (213) 545-0601

Join Our Newsletter

Expert Cloud Consulting

  • AWS Management Services
  • Descope Identity Solutions
  • Dropbox Business
  • Google Workspace
  • Global Relay
  • Microsoft 365 & Office 365
  • Okta IAM Solutions
  • Okta Partner Near You
  • Proofpoint Email Security

Cloud Technologies

  • Cloud Orchestration Engine
  • Cloud Products
  • Dropbox Business Platform
  • Google Workspace SMB
  • Microsoft 365 Platform
  • Microsoft Copilot AI
  • Okta Identity Platform
  • Proofpoint Email Security
  • Barracuda Email Protection

Micro Support

  • DNS Migration
  • Okta Backup
  • VPN Setup in AWS

Managed Cloud Services

  • Application SSO
  • Cloud Management
  • Cybersecurity Management
  • Spam Filter Comparison
  • Google Workspace
  • Microsoft Office 365
  • Okta Managed Services
  • 2-Hour Support Session

Workflow Automation

  • BambooHR to Okta Integration
  • Microsoft 365 Workflows
  • Okta Business Process Automation
  • Okta Workflow Consulting
  • Workday to Okta Integration

Migration & Infrastructure

  • Email Migration
  • Email Migration to Exchange Online
  • Exchange to Exchange Online Migration
  • Datto Protection

Connect With Us

  • X
  • Facebook
  • LinkedIn
  • YouTube

Microsoft Solutions

  • Exchange Online Plan 1
  • Exchange Online Plan 2
  • Microsoft 365 & Office 365
  • Microsoft 365 E3 Enterprise
  • Microsoft 365 E5 Enterprise
  • Microsoft 365 Kiosk
  • Office 365 E1 Business
  • Office 365 E5 Premium
  • View All Microsoft Plans & Pricing

Resources & Insights

  • Blog & Articles
  • Case Studies & Success Stories
  • Video Tutorials

Company Information

  • About Our Company
  • Careers & Opportunities
  • Project Management Portal
  • Technical Support

© 2026 | Iron Cove Solutions| Privacy | Simplifying Cloud-Based Intention

HomeEmailCall

  • Home
  • Consulting
  • Technology
  • Email Migration
  • Workflow
  • Resources
  • Support
  • Contact
Close