This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Office 365 mail protection

Hi all,

 

After deploy the XG firewall i can't add the followind domain on exception for the reverse proxy mail :

*.mail.protection.outlook.com

*.protection.outlook.com

 

I don't want add manually all the scopes IP of microsoft protection. Do you have a solution for add this domain with * on exeception because with the RDNS check i don't receive mail from O365 and hotmail.

 

Thanks for your help.

Regards.



This thread was automatically locked due to age.
Parents
  • Berlioz42300 said:
    Do you have a solution for add this domain with * on exeception because with the RDNS check i don't receive mail from O365 and hotmail.

    Sadly not. Wildcards for "Sources/Hosts" spam check exceptions are currently not allowed. We're experiencing the same issue with greylisting: https://community.sophos.com/products/xg-firewall/f/email-protection/103978/greylisting-and-office-365-senders

    But are you sure your RDNS checks are the problem? We don't have any problems with RDNS checks and Office 365 senders.

  • Yes i'm sure, if you use rDNS check Strict, all O365, hotmail and live mail are blocked and its normally.

     

    If you send an email by a domain on Office 365 (test.fr for this example), the IP who want send your email is : xxxx.mail.protection.outlook.com !

    Microsoft know this problem and palo alto are impacted too by this problem on reverse mail proxy.

    The only solutions is exclude all ip of microsoft protection (too many IP and /22 or /16...) or exclude a domain totally.

     

    The best solutions is exclude all domain xxxx.mail.protection.outlook.com but we need to wait an update for enter wildcard on exclusion MTA.

Reply
  • Yes i'm sure, if you use rDNS check Strict, all O365, hotmail and live mail are blocked and its normally.

     

    If you send an email by a domain on Office 365 (test.fr for this example), the IP who want send your email is : xxxx.mail.protection.outlook.com !

    Microsoft know this problem and palo alto are impacted too by this problem on reverse mail proxy.

    The only solutions is exclude all ip of microsoft protection (too many IP and /22 or /16...) or exclude a domain totally.

     

    The best solutions is exclude all domain xxxx.mail.protection.outlook.com but we need to wait an update for enter wildcard on exclusion MTA.

Children