How do I set up the inbound filter of EuropeanMX for Exchange Online (Microsoft 365)?


The following instructions explain how to create a partner connector and a transport rule in Exchange Online (Microsoft 365) and how to deactivate Safe-Link in order to receive email scout reports.


Before you start the configuration, you should ensure that you are a member of the role group Organisation Management in Microsoft 365 Defender Portal and Exchange Online.

Step 1: Create a partner connector and a transport rule to accept filtered messages

For more details on creating a partner connector and a rule in the classic EAC or the new EAC in Microsoft 365, please refer to Microsoft's documentation page, which you should read in full.

Creating a partner connector in the Exchange Admin Center

1

Log in to the Exchange Admin Center with your admin credentials.

2

Click on Mail Flow and then on Connectors.

3

Click on the plus sign (+) to add a connector.

4

Select the following:

  • Connection From - Partner Organisation
  • Connection To - Microsoft 365
5

Click on Next.

6

Assign a name and optionally a description for the connector (e.g. "EuropeanMX Incoming filter")


Make a note of the name of the connector, as you will need it later on!

7

Make sure that the setting What do you want to do after connector is saved is set to Turn it On.

8

Click on Next.

9

Select the option By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization and add the following IP address ranges via the plus sign (+), which we use for the delivery of incoming messages to your mail server:

130.117.251.9/25
185.201.16.0/22
    IP sub ranges:
    185.201.16.0/24
    185.201.17.0/24
    185.201.18.0/24
    185.201.19.0/24
192.69.18.0/24
208.70.90.0/24
45.91.121.0/24
45.93.148.0/24
45.131.180.0/24
45.140.132.0/24
193.41.32.0/24
185.225.27.0/24
80.91.219.0/24
188.190.113.0/24
45.147.95.0/24
46.229.240.0/24
87.236.163.0/24
188.190.112.0/24
192.69.19.0/24
208.70.91.0/24
185.209.51.0/24
185.218.226.0/24
10

Click on Next.

11

Ensure that the option Reject email messages if they aren't sent over TLS is active and click on Next.

12

Check all settings again and then click on Create Connector.

13

Click on Done.


Create a rule in Microsoft 365 Defender Security Portal

1

Log in to the Microsoft 365 Defender Security Portal with your admin access data.

2

Select the option Policies & Rules in the left-hand menu under Email & Collaboration.

3

Click on Threat Policies.

4

Now go to the area Rules and select the option Enhanced Filtering.

5

Now select the name of the connector that you created in step 1.

6

Click on the option Skip these IP addresses and enter the following IP address ranges:

185.201.16.0/22
192.69.18.0/24
208.70.90.0/24
45.91.121.0/24
45.93.148.0/24
45.131.180.0/24
45.140.132.0/24
193.41.32.0/24
185.225.27.0/24
80.91.219.0/24
188.190.113.0/24
45.147.95.0/24
46.229.240.0/24
87.236.163.0/24
188.190.112.0/24
192.69.19.0/24
208.70.91.0/24
185.209.51.0/24
185.218.226.0/24
130.117.251.9/25 (After adding, the IP address may change to 130.117.251.0/25. This is okay as both IPs belong to the same subnet.)
199.115.117.7/32
46.165.223.16/32
94.75.244.176/32




You must click on the IP address that matches the address entered for it to be added successfully.

7

Under Apply to theses users, select the option Apply to Entire Organisation.

8

Click on Save to save the settings.



An error when setting up the Partner Connector can result in messages from EuropeanMX not being delivered to the Microsoft servers.


Step 2: Change the MX records of your domain

In order to use the EuropeanMX inbound spam filter, the MX records of your domain must be replaced with the following records. Backup servers should not be used here, as spammers would otherwise have the opportunity to deliver spam messages directly to the backup server.

Global (recommended)

10 mx1.europeanmx.eu.
20 mx2.europeanmx.eu.
30 mx3.europeanmx.eu.
40 mx4.europeanmx.eu.

For redundancy reasons we recommend using our global data sets.

European Union

10 eu.mx1.europeanmx.eu.
20 eu.mx2.europeanmx.eu.
30 eu.mx3.europeanmx.eu.
40 eu.mx4.europeanmx.eu.

The numbers 10 - 40 represent the respective priority. Please pay attention to the dots at the end of the destination entry. Depending on the provider, these may be mandatory.

These 4 entries should be the only ones of type MX, others may have to be deleted. It is best to make a note of the original MX entries so that you can restore them later. If you have problems saving the MX entries, please contact your provider.


You can find more information in our FAQ entry "What are MX records and which ones should be used for incoming filtering?".


Step 3: Deactivate the processing of secure links by Microsoft Advanced Threat Protection

By using EuropeanMX and Microsoft 365, all links in incoming messages are scanned by Microsoft Advanced Threat Protection. However, when scanning the email scout reports, the tool triggers the links that are present in the reports, e.g. to approve and train messages or block senders. You can deactivate this behaviour with the following instructions:

1

Log in to the Exchange Admin Center with your admin access data.

2

Go to Mail flow and then to Rules.

  1. Select Add a rule.
  2. Select Create a new rule.
3

Enter a name, e.g. EuropeanMX ATP ESR bypass, in the dialogue box Set rule conditions .

4

Now make the following settings:

  • For the option Apply this rule if..., make the following settings:
    • Select The message headers.
    • Select Includes any of these words.
      • Enter List-Unsubscribe in the first text input field.
      • Enter lazaretto in the second text input field.
  • For the option Do the following..., make the following settings
    • Select Modify the message properties.
    • Select Set a message header.
      • Enter X-MS-Exchange-Organization-SkipSafeLinksProcessing in the first text input field.
      • Enter 1 in the second text input field.
  • Leave the option Except if blank.
  • Select Next.
5

Now define the rule settings suitable for your organisation and then click on Next.

6

Check the settings in the overview and then click on Next to apply the settings.