NOTE: Coordinate with the Paubox Team for inbound security setup.
- Paubox Team will provide the appropriate mx value
- Mail relays must be set on the Paubox side or mail will not be delivered
What you’ll need:
- Trial subscription with Paubox (don't have one? sign up here!)
- A Microsoft 365 account (Business Basic, Standard, or Premium)
- Microsoft 365: Admin access to your organization's Microsoft Exchange Admin (https://admin.exchange.microsoft.com/#/homepage)
- Domain: Admin access to your organization's Domain Host (for ex. GoDaddy or Cloudflare)
- The appropriate mx value for your domain - provided by Paubox during setup
Note: Make sure you can log into Microsoft 365 & Domain Host as an admin before proceeding. If you don’t have login credentials or permissions, reach out to who set up your Microsoft 365 account and/or website.
What you’ll do:
- Microsoft 365: Create an inbound routing rule
- Microsoft 365: Create a connector
- Domain: Update your domain's mx record
Questions? Stuck? We’re here for you! firstname.lastname@example.org
Part I: Microsoft 365 Inbound Routing rule
Office 365 may block the connection from Paubox's inbound mail servers to your email environment. In order to allow Paubox to relay inbound emails to your Office 365 environment, please follow the instructions below.
In the Admin Center, navigate to Mail flow > Rules.
Click + and then select Create a new rule.
- Give the rule a name Paubox Inbound Security
Under Apply this rule if, select The sender and then choose IP address is in any of these ranges or exactly matches.
In the specify IP addresses, specify the following IP addresses, click Add +, and then click ok.
Enter this IP range: 22.214.171.124/24
Under Do the following box, set the action by choosing Modify the message properties and then set the spam confidence level (SCL). In the specify SCL box, select Bypass spam filtering, and click ok.
Click the save button to save the rule. It appears in your list of rules.
- You need to enable the rule, and wait about 30 seconds for it to enable.
Part II: Office 365 - Create an Inbound Connector
- Log in to the Microsoft 365 Exchange Admin Center using admin-level credentials (https://admin.exchange.microsoft.com/#/homepage)
- In the navigation pane on the left, click mail flow. Then click connectors.
- Click + Add a connector
- On the pop-up window that follows, select
From: Partner Organization and To: Office 365. Then click Next
- Under *Name: enter Paubox Inbound. Make sure the checkbox labeled Turn it on is checked, then click Next
- Change the radio button to: "By verifying that the IP address of the sending server..." In the Add ip address field, enter 126.96.36.199/24 then click then the blue box with the + symbol
- Click Next
- On the next screen, keep Reject messages if they aren't using TLS selected, leave the other box unchecked. Click Next.
- On the next screen, click Create Connector
- Next click Done
- The Paubox inbound connector for Microsoft 365 is now live.
Part III: Domain Update - MX Record
If your organization’s domain name is example.com, Microsoft Office 365 asks you to setup your MX record like this:
MX 10 example-com.mail.protection.outlook.com.
To get Paubox inbound security going, you’ll need to change your MX record so that it has just one MX record:
<appropriate mx value supplied by Paubox Team during setup>
Note: if there are multiple MX records, edit the record of the lowest value (usually "10") and replace the existing value with mx.paubox.com. Save; then delete all other records of type MX.
This update will start routing all inbound email for your domain to Paubox when the DNS record change finishes propagating.
-- -- -- --
Legacy setups: mx1.paubox.com for IPs: 188.8.131.52, 184.108.40.206, 220.127.116.11