How to configure Libraesva ESG for Microsoft 365 (Office365) Print

  • Libraesva per 365, Microsoft 365 Libraesva
  • 7

 

Microsoft 365 Integration with Libraesva ESG

To properly integrate Microsoft 365 with Libraesva ESG, you need to configure DNS, relay settings, and connectors for both inbound and outbound mail flow.

 

Inbound Configuration

  • Log in to Microsoft 365 Admin with an administrator account.
  • Go to Show all options > Settings > Domains.
  • Select your domain and check the MX record.
  • The MX record will look like: yourdomain-com.mail.protection.outlook.com.
  • Access the Libraesva ESG web console: System > Mail Transport > Relay Configuration > Domain Relay.
  • Add or edit your domain and set the Mail Server field to the Microsoft 365 MX record.

Libraesva relay domain

This is the server where Libraesva ESG will forward all inbound email traffic.

 

Domain Antispoofing

Keep the setting Domain Antispoofing Standard (SPF), unless you are certain no external systems send mail on behalf of your domain.

 

Disable Microsoft 365 Antispam

Not mandatory, but recommended: disable Microsoft’s internal antispam for emails already scanned by Libraesva ESG to avoid false positives.

  1. In the Microsoft 365 portal, open Admin Center > Exchange.
  2. Go to Mail Flow > Rules and create a new rule.
  3. Assign a name, click More options....
  4. In Apply this rule if..., select The sender → IP address is....
  5. Enter the Libraesva ESG IP address.
  6. In Do the following, choose Set SCL → Bypass spam filtering.
  7. Save the rule.

Office 365 antispam rule

Repeat the configuration under Connection Filtering (direct link).

365 connection filtering

 

Configure Inbound Connector

Inbound connectors can be configured in two ways:

  • Production: accept mail only from Libraesva ESG (recommended).
  • Testing: allow mail also from other sources (not recommended in production).
  1. In Exchange Admin, go to Mail Flow > Connectors.
  2. Click [+] to create a new connector.
  3. From: Partner organization → To: Office 365.
  4. Give the connector a name.
  5. Use Sender domain: * to include all domains.
  6. Select Reject messages not sent from ESG IPs.
  7. Add the Libraesva ESG IP addresses.

Inbound connector

Inbound connector restrictions

 

Outbound Configuration

Every new rule or connector may take up to 1 hour to propagate across all Microsoft 365 nodes.

SPF Record

Update the SPF record in your DNS zone to include Libraesva. Always keep spf.protection.outlook.com in the record.

Example SPF record:

v=spf1 mx include:spf.protection.outlook.com include:spf.esvacloud.com -all

 


Was this answer helpful?

« Back