How to: Create an SMTP relay in O365 to allow a Scanner (or other device) to send email without TLS

Created by NHC IT Support, Modified on Tue, 17 May, 2022 at 9:14 AM by NHC IT Support

How to: Create an SMTP relay in O365 to allow a Scanner (or other device) to send email without TLS

Office 365 requires TLS, but many devices don't support this for sending email alerts. My Unitrends appliance doesn't, my Vipre AV console doesn't, nor does my SonicWALL UTM. Once an SMTP relay is setup inside O365 your devices will be able to send alerts over port 25.

--edit 9/11/17 - MS has changed the O365 menus, so I've updated the steps to reflect the changes.

17 Steps total

Step 1: Find your public static IP

The O365 SMTP relay only works with a static IP so if your ISP has you configured with a dynamic one you're out of luck.

Step 2: Log on to O365

Log on to O365 as an admin and select admin from the menu on the left.

Step 3: Select domains

On the left side of the screen select Setup, Domains.

Step 4: Choose a Domain from the list

If you have more than one, pick the one you want to use.

Step 5: Find your SMTP server

Under Required DNS settings, Exchange Online, you'll see an MX record - you want the Points To Address entry.

Step 6: Go to the Exchange Admin Center

In the upper right click on Admin, Exchange.

Step 7: Select mail flow

On the left side click on mail flow

Step 8: Select connectors

From the new menu in the middle of the screen click on connectors

Step 9: Add an inbound connector

Click on the plus sign under the Inbound Connectors heading

Step 10: Choose the connector type

You'll want to pick From Your organization's email server, To: Office 365

Step 11: Fill in the details

Give the connector a name so you can find it later and a detailed description if you want. Select the Turn On box if you want it to start working right away and uncheck the Retain box as it doesn't apply.

Step 12: Enter your static IP info

Select the By verifying that the IP... box then click the + to enter your static IP(s).

Step 13: Confirm settings

You should now have an inbound connector listed, looking something like this. Make sure each listed item is correct and confirm the IP addresses are correct, then click Save.

Step 14: Firewall exceptions

If your firewall is blocking outbound port 25 (it should be!) don't forget to enter exceptions for any device that you want to be able to send email through the relay. This will vary from firewall to firewall so I can't really include steps here.

The attached image is from my SonicWALL after I created the rule.

Step 15: Add SMTP server to your device

These next steps are for a Unitrends appliance, but the basic idea applies to any device you want to send from - find the SMTP settings and use what you found in step 5.

Log on to your appliance then click on Settings, Clients, Networking, and Notification

Step 16: Select SMTP server

Click on SMTP server

Step 17: Fill in the details

Enter the address from step 5 in the SMTP server box.

To make sure everything works put an address in the Test Address box and then click on the If you want to test your SMTP box.

Don't forget to click Confirm at the bottom!

You should now be able to use your new relay for any device or program that needs to send email from your network, but isn't capable of working with TLS.

If you want to read through all the details about the O365 relay setup, they are linked in the References section.

NOTE - You may also want to add the static IP (used in step 12) to the O365 SPAM white list, so your emails don't get flagged as SPAM.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article