To configure Outbound Inline with Hygiene mode:
What You Need
Administrative access to your O365/EOP account.
Administrative access to your Email Security - Cloud instance.
Step 1: Update the SPF record
For messages leaving the Email Security - Cloud outbound infrastructure to have high reputation, you must update the SPF record of the sending domain to contain the list of authorized senders' IP addresses.
Depending on the geographic region of your Email Security - Cloud account, add the following to your SPF records:
Email Security - Cloud region | SPF record | Example SPF record |
|---|---|---|
USA | _spf.fireeyecloud.com | v=spf1 include:_spf.fireeyecloud.com -all |
EMEA | ||
APJ | ||
USGOV | _spf.fireeyegov.com | v=spf1 include:_spf.fireeyecloud.com -all |
CA | _spf.fireeyecloud.com | v=spf1 include:_spf.fireeyecloud.com -all |
For more information, see the SPF documentation online.
Step 2: Create the IP allowlist rule
In the Microsoft Exchange admin center, select Other features. Click the link in the Connection filter row. The Anti-spam policies page in Microsoft Defender 365 opens.
Select Connection filter policy (Default).
Click Edit connection filter policy.
Enter the first IP address corresponding with the geographic region of your Email Security - Cloud account in the Always allow messages from the following IP addresses or address range entry box. Then, enter the remaining IP addresses.
Email Security - Cloud region
IP addresses
USA
34.223.9.0/24
34.223.11.128/25
34.223.12.0/25
100.25.99.0/25
100.24.127.128/25
EMEA
52.215.218.128/25
63.34.31.0/25
3.122.63.0/25
3.122.63.128/25
APJ
3.112.100.0/24
USGOV
15.200.33.0/24
CA
3.97.208.0/24
Click Save to save the rule configuration.
Step 3: Create an Inbound connector
In the Microsoft Exchange admin center, click Mail flow > Connectors.
Click +Add a connector to create a new connector.
Set the Connection from value to Partner organization.
The default Connection to value is Office 365. Click Next.
Enter the connector name and description (optional).
Verify the Turn it on check box is selected. Click Next.
Select By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization.
Enter the first sender IP address corresponding with the geographic region of your Email Security - Cloud account. Click the + button. Then, repeat for the remaining IP addresses.
Email Security - Cloud region
IP addresses
USA
34.223.9.0/24
34.223.11.128/25
34.223.12.0/25
100.25.99.0/25
100.24.127.128/25
EMEA
52.215.218.128/25
63.34.31.0/25
3.122.63.0/25
3.122.63.128/25
APJ
3.112.100.0/24
USGOV
15.200.33.0/24
CA
3.97.208.0/24
Click Next.
Verify that the Reject email messages if they aren't sent over TLS option is selected. Click Next.
Verify that the connector settings have been correctly configured, then click Create connector.
Click Done.
Step 4: Configure policies and domains in the Email Security - Cloud Web UI
This step includes 3 sub-steps:
Step 4a: Configure a Message Analysis Policy
Step 4b: Configure an Email Routing Configuration Policy
Step 4c: Add and Configure an Inbound Domain for Outbound Use
Important
The following message appears in the Create Policy page before you create an outbound message analysis or email routing configuration policy: Creation of outbound scanning policies, and associating those to domains will enable outbound scanning of emails. You acknowledge that such scans may from time to time result in quarantining or blocking of outbound emails. Completing the following steps indicates you acknowledge this statement.
Step 4a: Configure a message analysis policy
In the Email Security - Cloud Web UI, click Configuration, then select Policies from the drop-down menu.
Click Create Policy.
Select Outbound for Traffic Type.
Select Message Analysis for Rule Type.
Enter a policy name and description (optional) and click Create.
The policy configuration page appears. Several configuration fields, including Hygiene Settings and Rate Limit Settings, are auto-populated based on the size of your organization. To adjust these settings, select Manage next to Configuration.
Important
Hygiene mode is the default mode for outbound policies.
Step 4b: Configure an email routing configuration policy:
In the Email Security - Cloud Web UI, click Configuration, then select Policies from the drop-down menu.
Click Create Policy.
Select Outbound for Traffic Type.
Select Email Routing Configuration for Rule Type.
Enter a policy name and description (optional) and click Create.
The policy configuration page appears. Select Manage next to Email Routing Configuration.
Under Incoming Server Addresses, select Add.
Caution
If an email is sent by your organization from an IP address that is not listed in an outbound email routing configuration policy, the message will be rejected.
(Optional) Under Delivery Overrides, add next-hop destination servers where messages are delivered after the Email Security - Cloud hop. You can leverage third-party scanning solutions while also benefiting from Email Security - Cloud defenses. You can add A records, IP addresses, and MX records. Wildcard syntax is supported for each destination type. You can add multiple destinations for message delivery and determine the priority order under Delivery Overrides.
Important
You might run into an error when you use an O365 built-in MX record validator tool to cross-check the settings on the downstream MTA.
The validator tool usually checks if the MX records are pointing to the O365 mail properties instead of Email Security - Cloud.
If you have configured the MX records in the your internal O365 environment as per the documentation and have confirmed via outside sources that the domain MX records are pointing to the Email Security - Cloud correctly, this error can be ignored.
Caution
Email Security - Cloud cannot perform anti-spam/anti-virus scanning on emails after they are delivered to third-party tools.
Click Add. The Add Delivery Override Rule menu appears.
Enter recipient domains for mail delivery. To signify delivery to all domains in a destination (wildcard), enter an asterisk.
In the drop-down menu select what type of destination the recipient domains are associated with.
Enter destinations. Click Ok.
Under Deliver TLS Rules, enter the domains that you want to enforce TLS Encryption for.
Note
If a TLS connection cannot be established to the recipient domain, the connection will be dropped and the message will spool until a TLS connection can be made.
Click Manage next to Recipient Domains. The Manage Recipient Domains window appears.
Under Entries to Add, enter the domains that will have TLS rules enforced. (Optional) Use an asterisk to signify delivery to all domains is TLS enforced.
(Optional) Click Bulk Upload to upload a CSV file from your local machine. CSV files uploaded overwrite existing TLS settings.
Click OK.
In the policy configuration page, click Save. Allow up to 5 minutes for your changes to appear.
Step 4c: Add and configure an inbound domain for outbound use:
Important
You must provision a domain through inbound mode before enabling it for outbound use. However, you are not required to have inbound mail flow configured and enabled to provision a domain and set up outbound functionality.
To add and configure an inbound domain for outbound use:
In the Email Security - Cloud Web UI, click Configuration, then select Domains from the drop-down menu.
In the top-right corner, click Provision Domains.
In the Domain Mode section, select Inline with Hygiene.
In the Add Domains section, enter the domain(s) you want to use for outbound mail.
In the Domain Connection Settings section, select the Email Routing Policy you configured in Step 4b.
In the list of domains and domain groups, select the domain you want to use for outbound mail.
Configure the incoming and outgoing server addresses.
Click Save.
Open the Configuration > Domains page and select the domain you created.
The domain configuration page appears. Under Policies - Outbound, click Manage next to Message Analysis Policy.
In the configuration page, click Change to open the list of available message analysis policies.
Select the message analysis policy you configured in Step 4a and click Ok.
Step 4d: Generate a domain identification key
Unique domain identification keys are used to verify and secure your sender identity when sending outbound messages.
To generate a domain identification key:
Open the configuration page of the domain you selected for outbound use.
Under Policies - Outbound, click Generate Key. A unique, randomized identification key is generated.
Click Copy to copy the full identification key to your clipboard.
Important
You must include the domain identification key in the header of emails you want to send.
For example:
X-ETP-DOMAIN-AUTH-TOKEN: <identification-key>Outbound messages that do not include a domain identification key in the header are rejected by Email Security - Cloud.
Step 5: Create an Outbound connector
In the Microsoft Exchange admin center, click Mail flow > Connectors.
Click +Add a connector to create a new connector.
Set the Connection from value to Office 365.
Set the Connection to value to Partner organization. Click Next.
Enter the connector name and description (optional).
Verify the Turn it on check box is selected. Click Next.
Verify that the Only when I have a transport rule set up that redirects messages to this connector option is selected. Click Next.
Select Route email through these smart hosts.
Enter the smart host corresponding with the geographic region of your Email Security - Cloud account. Click the + button. Then, click Next.
Email Security - Cloud region
Smart host
USA
mx.us.email-out.fireeyecloud.com
EMEA
mx.emea.email-out.fireeyecloud.com
APJ
mx.ap.email-out.fireeyecloud.com
USGOV
mx.us.email-out.etp.fireeyegov.com.
CA
mx.ca.email-out.fireeyecloud.com
Verify that the Always use Transport Layer Security (TLS) to secure the connection (recommended) option is selected.
Verify that the Issued by a trusted certificate authority (CA) option is selected. Click Next.
Depending on the geographic region of your Email Security - Cloud account, enter one of the following email addresses, then click +.
Email Security - Cloud region
Email address
USA
o365@validate.fireeyecloud.com
EMEA
o365@validate.emea.fireeyecloud.com
APJ
o365@validate.ap.fireeyecloud.com
USGOV
o365@validate.fireeyegov.com
CA
o365@validate.ca.fireeyecloud.com
Click Validate to begin the validation process.
Note
Validation results should indicate that both the connectivity and email tests were successful. If results are not successful, verify that the
X-ETP-DOMAIN-AUTH-TOKEN: <identification-key>is included in the validation email headers. See Step 4d for more information. If both tests still do not complete successfully, please contact Trellix Customer Support for further help.Click Next after validation is complete. Review the connector settings. Then, click Create connector.
Step 6: Create individual outbound transport rules for each sender domain
Important
You must repeat this step for each individual domain in your organization.
In the Microsoft Exchange admin center, select Mail flow > Rules.
Click +Add a rule, then select Create a new rule in the drop-down menu.
Enter a name for the rule.
Under the Apply this rule if... section:
Select The sender > is external/internal from the drop-down menu. A pop-up window appears.
Select Inside the organization from the select sender location drop-down menu.
Click Save.
Click the + button to the right of the Apply this rule if section. A new section titled And appears.
Select The recipient > is external/internal. A pop-up window appears.
Select Outside the organization from the select sender location drop-down menu.
Click Save.
Click the + button to the right of the Apply this rule if section. A new section titled And appears.
Select The sender > domain is.
Enter your organization's domain. Click Add.
Click Save.
Under the Do the following section:
Select Modify the message properties > set a message header.
Next to Set the message header, select Enter text.
In the message header pop-up window, enter the message header as
X-ETP-DOMAIN-AUTH-TOKENexactly. Click Save.Next to to the value, select Enter text.
In the message header pop-up window, enter the domain identification key generated in Step 4d.
Click the + button to the right of the Do the following section. A new section titled And appears.
Select Redirect the message to > the following connector.
In the drop-down menu, select the outbound connector you created in Step 5.
Click Save.
Click Next.
Important
Do not select Stop processing more rules. Doing so may interfere with how O365 processes spam messages.
In the Match sender address in message drop-down menu, select header or envelope.
Important
Do not change any other default settings after Step 10.
Click Next.
Click the Save button. Review the rule configuration. Click Finish.
Verify the rule is enabled and that it comes before any transport rules or rules that have the stop processing option selected.
Important
You must repeat this step for each individual domain in your organization.