Quick answers
Microsoft 365
What the integration adds
What stays as it is
- Your MX records. Email keeps arriving at M365 first. A mail flow rule hands it to xorlab over the connector, and xorlab hands it back to M365 for delivery. There is nothing to change at your DNS provider, no TTL to plan around and no cutover moment.
- Your outbound sending identity. Outgoing email also returns to M365 for final delivery, so your public sending IPs, your SPF record and your DKIM signatures are unchanged.
- Exchange Online Protection and Defender. Microsoft’s own filtering keeps running. The only policy xorlab touches is optional: Move M365 Quarantine to xorlab changes the spam actions so that users have a single quarantine instead of two.
- Mailboxes, addresses and licenses. Nothing is migrated and no mailbox is created for your users. The only new mailbox is the optional reporting mailbox.
- Accepted domains, SPF and the connection filter. A standard integration does not touch them. The three adjustments under troubleshooting are needed only if you run into deliverability issues.
- Your clients. No add-in is rolled out. Users report suspicious email with the button M365 already provides.
Hybrid setupsFollow the M365 path whenever you receive and send email through M365, even if mailboxes also exist on premises. If email enters and leaves through your own infrastructure, follow On-premises instead.
How to undo it
Disable the two mail flow rules in the Exchange admin center. Email returns to its previous path within minutes, without a DNS change. The connectors and the Entra ID app can then be removed at your own pace.On-premises
How much changes depends on where xorlab sits in your mail flow. You choose that in Set Up Email Routing in xorlab.What the integration adds
What stays as it is
- Your existing gateway or filter, unless you deliberately replace it. In the default inline add-on setup, xorlab is added next to what you already run.
- Mailboxes, addresses and clients. Nothing is migrated and nothing is installed on Exchange or on the endpoints.
- The mail flow itself, in Monitoring mode. xorlab only receives a copy and never modifies, delays or blocks an email.
Monitoring mode and availabilityThe copies are ordinary emails, so if all xorlab MTAs are unreachable, they can queue up on the system that sends them. If that happens, disable the BCC rules temporarily.
How to undo it
In Monitoring mode, disable the BCC mail flow rules or the ESA message filter. In Inline mode, set the next hop of the system in front of xorlab back to its previous destination and disable the send connector that points at xorlab.What your users notice
- In Monitoring mode, nothing. No email is modified, delayed or blocked.
- In Inline mode, with the delivered defaults:
- Emails with a malicious verdict are quarantined instead of delivered. Which verdict and confidence leads to which action is visible, and adjustable, in Review Default Actions.
- Some verdicts are delivered with a subject prefix such as
[SPAM], configured on the same screen. - Nothing else is added to the message. Enable Contextual Banners and Add Result Header to Email are separate, optional steps and are off by default.
- Only if you enable it: the Self-Service Quarantine (SSQ) lets users see and release their own quarantined emails, and quarantine notifications are sent to them.
#quarantine before switching protection on.
Next steps
Before You Begin
Configure your guarded domains, set the data retention, and choose between Inline and Monitoring mode.