Microsoft 365

High Volume Email for Microsoft 365: set up HVE for app and device mail

Create High Volume Email accounts, connect pay-as-you-go billing, choose basic auth or OAuth, and point printers and line-of-business apps at the HVE endpoint for internal mail.

11 min read
On this page

High Volume Email (HVE) lets applications and devices send large volumes of internal email through Exchange Online without using a licensed user or shared mailbox. You create an HVE account in the Exchange admin center or with New-MailUser -HVEAccount, attach a pay-as-you-go billing policy, and point the app at smtp.hve.mx.microsoft on port 587 with TLS, authenticating with the account password or an OAuth token. HVE has no recipient or message rate limit, but it delivers only to recipients inside your own tenant.

Who this is for and what you will have

This guide is for Exchange Online administrators who look after the mail that payroll systems, monitoring tools, HR platforms, scanners and other line-of-business applications send to employees. These senders often run on a shared mailbox with SMTP AUTH today and keep hitting per-mailbox sending limits. They are also affected by Microsoft's plan to switch SMTP AUTH Basic authentication off by default at the end of December 2026.

At the end you will have:

  • Pay-as-you-go billing connected to the High Volume Email service.
  • One or more HVE accounts, each with a valid billing policy and an Active status.
  • An application or device that sends through the HVE endpoint with basic authentication or OAuth.
  • A list of the errors that HVE returns and what each one means.

If you are still deciding between HVE, SMTP AUTH, Direct Send and a relay connector, read SMTP AUTH vs Direct Send vs relay connector first.

What HVE can and can't do

HVE is designed for automated, transactional and operational messages: payroll and HR notifications, IT alerts, application messages, scan-to-email and security notifications. Each HVE account is a mail-enabled user object with no mailbox, so application mail stays separate from user mailboxes.

LimitValue
Recipient rate limitNone
Message rate limitNone
HVE accounts per tenantUp to 100
Recipients per messageUp to 50
Maximum message size10 MB
Recipient scopeInternal recipients within the tenant only
ConnectionsUp to 100 concurrent per IP address, or up to 250 authenticated per tenant

Some restrictions affect design decisions:

  • Internal recipients only. HVE can't relay to the internet. Mail to external addresses needs a different path, such as Azure Communication Services Email.
  • No mailbox. An HVE account can't receive mail, and messages aren't saved to a Sent Items folder. If people need to reply, set a Reply-To address on the account.
  • No group membership. You can't add HVE accounts to distribution lists or mail-enabled security groups.
  • Worldwide only. Microsoft supports HVE in the Microsoft 365 Worldwide (standard multi-tenant) environment. Other clouds are still under evaluation.

To work within the 50-recipient limit, send to a single distribution list or dynamic distribution list. Keep in mind that billing counts recipients after the list is expanded. If you can't use lists, split the recipients into batches of no more than 50 per message.

HVE traffic also doesn't count toward the tenant-wide outbound quota. The Exchange Team FAQ confirms that HVE messages aren't counted against the Tenant External Recipient Rate Limit, which is covered in Tenant External Recipient Rate Limit (TERRL).

Prerequisites

  • Exchange Online admin rights to create mail users and use the Exchange admin center.
  • A role that can manage pay-as-you-go billing in the Microsoft 365 admin center: SharePoint Administrator, Billing Administrator, AI Administrator or Global Administrator.
  • An Azure subscription in the same tenant, plus a resource group, with Owner or Contributor rights on both. You can create either one while you set up the billing policy.
  • At least one SharePoint license (or a license that includes SharePoint) in the tenant. Pay-as-you-go setup requires it, and HVE billing validation fails with NoSPOLicenseFound without it.
  • An accepted domain for the HVE account's address, for example contoso.com.
  • The Exchange Online PowerShell module if you want to script the setup.

Billing matters. Microsoft's troubleshooting article states that HVE billing began on June 1, 2026, and that from that date billing policies are required. An account without a valid policy shows Not active and can't send.

Step 1: Connect pay-as-you-go billing

HVE is billed per expanded delivered recipient at USD 0.000042 each (USD 42 per million recipients), charged to the Azure subscription behind the billing policy.

  1. In the Microsoft 365 admin center, go to Billing > Pay-as-you-go.
  2. On the Billing policies tab, select Add a billing policy. Enter a name, choose the Azure Subscription, Resource group and Region, accept the terms and select Next.
  3. Leave All users on the Choose users page. User selection applies only to Copilot services.
  4. Optionally set a budget and alert recipients. A budget only sends alerts. Reaching 100% doesn't stop the service or the billing.
  5. Review the policy and select Create policy.
  6. On the Services tab, find High Volume Email, select Connect a policy, set the policy's Connection status toggle to Connected, and select Save.

One billing policy can serve many HVE accounts, but each account can have only one policy. Create separate policies when you need costs to land in different Azure subscriptions.

Step 2: Create the HVE account

In the Exchange admin center

  1. Open the Exchange admin center at https://admin.exchange.microsoft.com/.
  2. Go to Mail flow > High Volume Email and select Add an HVE account.
  3. Enter a Display name, a Primary email address in an accepted domain (for example hve-payroll@contoso.com), an optional Alias and a Password. The password is used only for basic SMTP authentication and must meet your organization's password policy.
  4. On the Pay-as-you-go billing policy step, pick the policy from Step 1. You can skip this step and assign the policy later, but the account can't send until you do.
  5. Review and select Create.

In Exchange Online PowerShell

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
# Create the account with a password entered as a secure string
$securePassword = Read-Host "Enter password" -AsSecureString
New-MailUser -HVEAccount -Name "HVE Payroll" -Password $securePassword -PrimarySmtpAddress "hve-payroll@contoso.com"
 
# Find HVE billing policies and assign one
Get-BillingPolicy -ResourceType HVE
Set-HVEAccountBillingPolicy -Identity hve-payroll@contoso.com -BillingPolicyId "11111111-1111-1111-1111-111111111111"
 
# Send replies to a monitored mailbox
Set-HVEAccountSettings -Identity hve-payroll@contoso.com -ReplyTo "payroll-team@contoso.com"

If the tenant uses a federated domain, Microsoft documents creating the account with a federated-domain address directly, or switching it later with Set-MailUser -HVEAccount -Identity <address> -PrimarySmtpAddress <federated address>. The primary SMTP address can be changed only in PowerShell, not in the EAC.

Create one HVE account per application or environment. Separate accounts make the usage report easier to read and let you rotate one app's credentials without touching the others.

Step 3: Choose an authentication method

HVE supports basic authentication (account password) and OAuth. Microsoft recommends OAuth where the application supports it.

Before you choose, check your tenant settings:

  • Security defaults in Microsoft Entra ID disable all basic authentication, including SMTP. With security defaults on, HVE accepts only OAuth.
  • Authentication policies can block basic SMTP. If you use them, make sure the policy that applies to the HVE account has AllowBasicAuthSmtp enabled. You can apply a custom authentication policy just to HVE accounts.
  • SmtpClientAuthenticationDisabled in Set-TransportConfig doesn't affect HVE, because HVE uses a dedicated endpoint.

Configure OAuth

  1. In the Microsoft Entra admin center, go to Identity > Applications > App registrations > New registration and register the application.
  2. Under API permissions, select Add a permission > APIs my organization uses, search for Office 365 Exchange Online and add Mail.Send:
    • Application permission for apps that use a client secret. Add the secret under Certificates & secrets.
    • Delegated permission for apps that sign in with the HVE account's own credentials. Also enable Allow public client flows on the Authentication tab.
  3. Select Grant admin consent.
  4. The application requests a token for the audience https://outlook.office.com/.default.

Granting the application permission doesn't let the app send as every mail user. Microsoft states that with this configuration only HVE account mail users can send, unless you explicitly authorize the app for other mail users through application access policies or RBAC for Applications.

To prevent other applications from using a particular HVE account, add an allow list. You can list up to 10 applications per account. Use the service principal object ID from the Enterprise applications blade, not the object ID from App registrations:

Add-HVEAppAccess -Identity hve-payroll@contoso.com -AppIds 00000000-0000-0000-0000-000000000001
Get-HVEAccountSettings -Identity hve-payroll@contoso.com | Format-List *AllowedApps*

Allowed applications apply to OAuth only. Basic authentication with the password isn't affected.

The client authenticates with the AUTH XOAUTH2 command, using this base64-encoded string (^A is the Control+A character):

base64("user=" + userName + "^Aauth=Bearer " + accessToken + "^A^A")

Step 4: Configure the application or device

SettingValue
SMTP server (smart host)smtp.hve.mx.microsoft (recommended); smtp-hve.office365.com will be deprecated
Port587
TLS/StartTLSEnabled
AuthenticationHVE account credentials or OAuth token

Use the smtp.hve.mx.microsoft host name for new configurations so you don't have to update devices again when the older name is retired.

Verify

  1. In the EAC, go to Mail flow > High Volume Email and confirm that the account shows a billing policy name and an Account status of Active.
  2. Send a test message from the application to an internal mailbox and confirm it arrives.
  3. In the EAC, go to Reports > Mail flow > High Volume Email. Choose a time period (7, 30 or 90 days, or a custom start date), switch between Recipient volume and Message volume, and select the account to see its usage next to the tenant total.
  4. In PowerShell, check the billing state:
Get-HVEAccountBillingPolicy -Identity hve-payroll@contoso.com

A BillingPolicyStatus of BillingPolicyValid means the policy is assigned and the subscription is active.

Troubleshooting

Authentication errors

ErrorCause and fix
535 5.7.3 Authentication unsuccessfulWrong credentials, or basic authentication is blocked. Check security defaults and the authentication policy that applies to the account.
535 5.7.139 Authentication unsuccessful, the organization configuration doesn't allow this authentication request.Basic authentication is blocked by tenant configuration. Microsoft's documented fix is to turn off security defaults or allow AllowBasicAuthSmtp in the applicable authentication policy. Moving the app to OAuth avoids the need to weaken either setting.
501 5.5.121 to 501 5.5.126The XOAUTH2 string is malformed: not base64, wrong field order, or missing user, Bearer keyword or token. Rebuild it in the format shown above.
535 5.7.142 / 535 5.7.143The token is about to expire or has expired. Request a new token, and keep SMTP sessions shorter than the token lifetime.
535 5.7.144Invalid API permissions. Check that Mail.Send from Office 365 Exchange Online is granted with admin consent and that the permission type matches the token flow.
550 5.7.240The application is not allowed for this HVE account. Add its service principal ID with Add-HVEAppAccess.

Billing states

If an account shows Not active, read BillingPolicyStatus from Get-HVEAccountBillingPolicy:

StatusMeaning
NoProperBillingPolicyStoredNo policy assigned. Assign one in the EAC or with Set-HVEAccountBillingPolicy.
BillingPolicyNotFoundThe assigned policy was deleted.
BillingPolicyMismatchedThe policy retrieved doesn't match the expected tenant or policy identity. Microsoft describes this as uncommon.
NoConnectedBillingPolicyFoundThe policy isn't connected to High Volume Email in Billing > Pay-as-you-go.
SubscriptionIsNotActiveThe Azure subscription behind the policy is inactive or deleted.
NoSPOLicenseFoundThe tenant has no SharePoint license, so the policy can't be validated.

The device still can't send

Check the host name, port 587 and TLS on the device itself, and confirm that the credentials or token are valid. Microsoft also suggests testing the HVE account separately from the device with the SMTP connector in Power Automate. If that test works, the problem is on the device.

Checklist

  • Pay-as-you-go billing policy created and connected to High Volume Email
  • One HVE account per application, in an accepted domain, with no license assigned
  • Billing policy assigned and account status Active
  • Authentication chosen: OAuth with an allowed-applications list, or basic auth with security defaults and authentication policies checked
  • Reply-To set where recipients may answer
  • Devices pointed at smtp.hve.mx.microsoft:587 with TLS
  • Recipients batched to 50 per message or sent to a distribution list
  • External recipients routed through another service
  • HVE usage report reviewed after the first week

References

Questions people ask

Can High Volume Email send to external recipients?

No. HVE delivers only to recipients inside your own tenant, and Microsoft states that HVE accounts can't be used for external email delivery. If an application must reach customers or partners outside the tenant, use Azure Communication Services Email or another sending method instead.

Does an HVE account need a Microsoft 365 license?

No. An HVE account is a mail user object without a mailbox, and Microsoft recommends that you don't assign licenses to it. Instead, each HVE account needs a pay-as-you-go billing policy linked to an Azure subscription, or it can't send mail.

How much does High Volume Email cost?

HVE uses Microsoft 365 pay-as-you-go billing. Microsoft lists the price as USD 0.000042 per expanded delivered recipient, which is USD 42 per one million recipients. Recipients reached through a distribution list are counted after the list is expanded.

Does HVE still work if SMTP AUTH is disabled in my tenant?

Yes. HVE uses its own SMTP endpoint, so HVE accounts can authenticate even when SmtpClientAuthenticationDisabled is True in the transport configuration. Security defaults and authentication policies still apply, so basic authentication only works if neither of them blocks it.

Exchange OnlineHigh Volume EmailSMTPExchange Online PowerShell
  1. Calendar permissions in Exchange Online: Add-MailboxFolderPermission guide

    Share calendars, change the organization-wide Default permission and add calendar delegates in Exchange Online with Add-, Set- and Remove-MailboxFolderPermission, including localized folder names.

    Microsoft 3659 min read
  2. Convert a user mailbox to a shared mailbox and remove the license safely

    Keep a leaver's email and calendar in Exchange Online without paying for a license: secure the account, convert the mailbox, grant access, then remove the license in the right order.

    Microsoft 36511 min read
  3. EWS retirement in Exchange Online: find EWS apps and set EWSAllowedAppIDs

    Find every app that still calls Exchange Web Services, build an EWSAllowedAppIDs allow list and set EWSEnabled so critical apps keep working while EWS is switched off from October 2026.

    Microsoft 36513 min read