Skip to main content
The integration is done via mail flow rules and connectors.
Prerequisites

Choose how to configure it

Both paths create the same two connectors and the same two mail flow rules. Pick one.

Quick integration with PowerShell

Run one script that asks for your values. Mail flow rules need to be activated manually.

Manual integration in the Exchange Admin Center

The same configuration manually in the web interface. Use it if you prefer to see each setting before you apply it.

Quick integration with PowerShell

One script creates both connectors and both mail flow rules. It asks for your values, shows a summary and changes nothing until you confirm. You need the Exchange Administrator role and the ExchangeOnlineManagement module. Run it either in a PowerShell window on your own machine or in the Azure Cloud Shell.
Run these once, in a PowerShell window on your own machine. Everything installs for your user account only, so you do not need local administrator rights:
  1. Download the script with the command on Script Downloads, which requires you to log in. Run that command in your PowerShell window, then come back here and start the script. If you are not signed in to Exchange Online yet, a sign-in window opens first:
    If one of the connectors or rules already exists in your tenant, the script stops without changing anything.
  2. Answer the prompts:
  3. Check the summary and confirm with y. The script then:
    • creates the xorlabToMicrosoft365 and Microsoft365Toxorlab connectors
    • validates Microsoft365Toxorlab and summarizes the result
    • creates the IncomingToxorlab and OutgoingToxorlab mail flow rules, disabled
    In the validation summary, the connectivity check should succeed. The test email can fail at this point; if it does, validate the connector again in the Exchange Admin Center once the mail flow rules are enabled. The Exchange Admin Center shows the connector as not validated until you validate it there.
  4. Enable both rules:
    This is the step that puts xorlab in the delivery path. It can take several minutes until the rules are active. Test them by sending an incoming and an outgoing email.
If M365 rejects emails from xorlab afterward, or files them as junk, see Troubleshooting. To remove the connectors and mail flow rules again, run ./xorlabExoSetup.ps1 -Mode Inline -Remove.

Test with one mailbox first

With the test scope, each rule gets one extra condition on top of its organization-wide ones: IncomingToxorlab matches only email to the test mailbox, and OutgoingToxorlab only email from it. All other email keeps its normal mail flow. When you are done testing, remove that condition and the same rules apply to the whole organization. Either delete it in the Exchange Admin Center under Mail flow → Rules — The recipient → is this person on the incoming rule, The sender → is this person on the outgoing one — or run:

Manual integration in the Exchange Admin Center

Create xorlab to M365 connector

This connector makes sure that M365 will accept emails from xorlab.
  1. Go to Exchange Admin Center → Connectors → add a connector: Add a connector
  2. Connection from → Your organization’s email server: New connector
  3. Set the name to xorlabToMicrosoft365 and enable Retain internal Exchange email headers: Connector name
  4. Choose By verifying that the subject name… and add *.xyz.activeguard.cloud where xyz is your customer ID: Authenticating sent email
  5. Create connector.

Create M365 to xorlab connector

This connector makes sure that all emails are routed through xorlab.
  1. Create a new connector.
  2. Connection from → Office 365, and Connection to → Your organization’s email server: New connector from M365
  3. Set the name to Microsoft365Toxorlab and enable Retain internal Exchange email headers: Connector name from M365
  4. Select Only when I have a transport rule set up…: Use of connector
  5. Add a new smart host with the value mx.xyz.activeguard.cloud, where xyz is your customer ID: Routing
  6. Activate Always use Transport Layer Security… and select Issued by a trusted certificate authority (CA): Security restrictions
  7. Enter a company mailbox where a validation email should be sent to: Validation email
    Unsuccessful validationThe connector validation might fail at this point. If this happens, save the connector without validation, create the mail flow rule in the next section and then validate the connector again.
  8. Review the connector and click Create when it’s OK.

Create mail flow rules

Here we create mail flow rules that use the connector from above. The mail flow rules make sure that there is no loop between xorlab and M365.
  1. Go to Exchange Admin Center → Mail flow → Rules and create a new rule: Creating a new rule
  2. Configure the rule like this:
    • Name: IncomingToxorlab
    • Apply this rule if → The sender → is external/internal → Outside the organization
    • Click the plus icon (+) to add another condition
    • And → The recipient → is external/internal → Inside the organization
    • Do the following → Redirect the message to → the following connector → choose Microsoft365Toxorlab
    • Click the plus icon (+) to add another action
    • And → Modify the message properties → set a message header → set x-xor-tenant-token to your header value
    • Except if → The sender → IP address is in any of these ranges… → add all IPs of the xorlab MTAs (find them in the DNS A records of mx.xyz.activeguard.cloud)
    New rule
  3. Click through Next → Finish and leave all settings at their defaults.
  4. Repeat steps #2-3 to add another rule but this time set:
    • Name: OutgoingToxorlab
    • The sender → Inside the organization
    • The recipient → Outside the organization
    • Except if → The sender → IP address is in any of these ranges… → the same xorlab MTA IPs as in step #2
    • Click the plus icon (+) to add another exception
    • The message properties → Automatic Reply
    Outgoing rule
  5. Enable both rules in the Rules page.
  6. It can take several minutes until the rule is active. Test it by sending an incoming and outgoing email.

Troubleshooting

Apply the following measures only if you experience deliverability issues between M365 and xorlab. Normally, they are not necessary.

M365 rejects emails from xorlab

If M365 rejects some legitimate emails from xorlab, there are multiple measures. Apply them in order written below until the problem is fixed. First, add your xorlab domain as an “accepted domain”.
  1. Go to Microsoft 365 Admin Center → Settings → Domains and add a domain: add-domain
  2. Enter xyz.activeguard.cloud, where xyz is your customer ID: Add a domain name
  3. Select the first option Add a text record…: Domain verification method
  4. Send the TXT value to support@xorlab.com so that we can add it to the DNS record of your domain. After this has been done, verify: Domain verification data
  5. After a successful verification, click More options and select Skip and do this later: Domain skip and do this later
If that does not help, you can add xorlab to your SPF records.
You can add the xorlab MTAs to your SPF records. For this, include a:mx.xyz.activeguard.cloud to all your domains that route emails via xorlab:
Afterward, check that your SPF records are still valid, for example with DMARCanalyzer’s SPF checker.
If adding xorlab to your SPF record did also not help, you can add xorlab to the anti-spam policy of M365.
  1. Go to Anti-spam policies and select Connection filter policy (Default): Anti-spam policies
  2. Click Edit connection filter policy: Connection filter policy
  3. Enter the xorlab MTA IPs to the first field: Allowed IPS for connection cilter
  4. Check if the addresses are correct under IP Allow list and click Close.

M365 puts emails from xorlab into Junk

The following mail flow rule will bypass the M365 spam filtering for emails coming from xorlab. Note that this will mostly disable the Junk folder mechanism for your mailboxes.
  1. Go to Exchange Admin Center → Mail flow → Rules and create a new rule: Creating a new rule
  2. Configure the rule like this:
    • Name: SpamBypassxorlab.
    • Apply this rule if → The sender → IP address is in any of these ranges… → add all IPs of the xorlab MTAs
    • Click the plus icon (+) to add another condition
    • And → The message properties → include an SCL greater than or equal to → Bypass spam filtering
    • Do the following → Modify the message properties → set the spam confidence level (SCL) → Bypass spam filtering Bypass spam filtering actions
  3. Click through Next → Finish and leave all settings at their defaults.
  4. Enable the rule in the Rules page.

Next steps

Optionally continue with: Once the integration is complete, continue with What to Configure Next.