High Volume Email (HVE) lets applications and devices send large volumes of internal email through Exchange Online without using a licensed user or shared mailbox. You create an HVE account in the Exchange admin center or with New-MailUser -HVEAccount, attach a pay-as-you-go billing policy, and point the app at smtp.hve.mx.microsoft on port 587 with TLS, authenticating with the account password or an OAuth token. HVE has no recipient or message rate limit, but it delivers only to recipients inside your own tenant.
Who this is for and what you will have
This guide is for Exchange Online administrators who look after the mail that payroll systems, monitoring tools, HR platforms, scanners and other line-of-business applications send to employees. These senders often run on a shared mailbox with SMTP AUTH today and keep hitting per-mailbox sending limits. They are also affected by Microsoft's plan to switch SMTP AUTH Basic authentication off by default at the end of December 2026.
At the end you will have:
- Pay-as-you-go billing connected to the High Volume Email service.
- One or more HVE accounts, each with a valid billing policy and an Active status.
- An application or device that sends through the HVE endpoint with basic authentication or OAuth.
- A list of the errors that HVE returns and what each one means.
If you are still deciding between HVE, SMTP AUTH, Direct Send and a relay connector, read SMTP AUTH vs Direct Send vs relay connector first.
What HVE can and can't do
HVE is designed for automated, transactional and operational messages: payroll and HR notifications, IT alerts, application messages, scan-to-email and security notifications. Each HVE account is a mail-enabled user object with no mailbox, so application mail stays separate from user mailboxes.
| Limit | Value |
|---|---|
| Recipient rate limit | None |
| Message rate limit | None |
| HVE accounts per tenant | Up to 100 |
| Recipients per message | Up to 50 |
| Maximum message size | 10 MB |
| Recipient scope | Internal recipients within the tenant only |
| Connections | Up to 100 concurrent per IP address, or up to 250 authenticated per tenant |
Some restrictions affect design decisions:
- Internal recipients only. HVE can't relay to the internet. Mail to external addresses needs a different path, such as Azure Communication Services Email.
- No mailbox. An HVE account can't receive mail, and messages aren't saved to a Sent Items folder. If people need to reply, set a Reply-To address on the account.
- No group membership. You can't add HVE accounts to distribution lists or mail-enabled security groups.
- Worldwide only. Microsoft supports HVE in the Microsoft 365 Worldwide (standard multi-tenant) environment. Other clouds are still under evaluation.
To work within the 50-recipient limit, send to a single distribution list or dynamic distribution list. Keep in mind that billing counts recipients after the list is expanded. If you can't use lists, split the recipients into batches of no more than 50 per message.
HVE traffic also doesn't count toward the tenant-wide outbound quota. The Exchange Team FAQ confirms that HVE messages aren't counted against the Tenant External Recipient Rate Limit, which is covered in Tenant External Recipient Rate Limit (TERRL).
Prerequisites
- Exchange Online admin rights to create mail users and use the Exchange admin center.
- A role that can manage pay-as-you-go billing in the Microsoft 365 admin center: SharePoint Administrator, Billing Administrator, AI Administrator or Global Administrator.
- An Azure subscription in the same tenant, plus a resource group, with Owner or Contributor rights on both. You can create either one while you set up the billing policy.
- At least one SharePoint license (or a license that includes SharePoint) in the tenant. Pay-as-you-go setup requires it, and HVE billing validation fails with
NoSPOLicenseFoundwithout it. - An accepted domain for the HVE account's address, for example
contoso.com. - The Exchange Online PowerShell module if you want to script the setup.
Billing matters. Microsoft's troubleshooting article states that HVE billing began on June 1, 2026, and that from that date billing policies are required. An account without a valid policy shows Not active and can't send.
Step 1: Connect pay-as-you-go billing
HVE is billed per expanded delivered recipient at USD 0.000042 each (USD 42 per million recipients), charged to the Azure subscription behind the billing policy.
- In the Microsoft 365 admin center, go to Billing > Pay-as-you-go.
- On the Billing policies tab, select Add a billing policy. Enter a name, choose the Azure Subscription, Resource group and Region, accept the terms and select Next.
- Leave All users on the Choose users page. User selection applies only to Copilot services.
- Optionally set a budget and alert recipients. A budget only sends alerts. Reaching 100% doesn't stop the service or the billing.
- Review the policy and select Create policy.
- On the Services tab, find High Volume Email, select Connect a policy, set the policy's Connection status toggle to Connected, and select Save.
One billing policy can serve many HVE accounts, but each account can have only one policy. Create separate policies when you need costs to land in different Azure subscriptions.
Step 2: Create the HVE account
In the Exchange admin center
- Open the Exchange admin center at
https://admin.exchange.microsoft.com/. - Go to Mail flow > High Volume Email and select Add an HVE account.
- Enter a Display name, a Primary email address in an accepted domain (for example
hve-payroll@contoso.com), an optional Alias and a Password. The password is used only for basic SMTP authentication and must meet your organization's password policy. - On the Pay-as-you-go billing policy step, pick the policy from Step 1. You can skip this step and assign the policy later, but the account can't send until you do.
- Review and select Create.
In Exchange Online PowerShell
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
# Create the account with a password entered as a secure string
$securePassword = Read-Host "Enter password" -AsSecureString
New-MailUser -HVEAccount -Name "HVE Payroll" -Password $securePassword -PrimarySmtpAddress "hve-payroll@contoso.com"
# Find HVE billing policies and assign one
Get-BillingPolicy -ResourceType HVE
Set-HVEAccountBillingPolicy -Identity hve-payroll@contoso.com -BillingPolicyId "11111111-1111-1111-1111-111111111111"
# Send replies to a monitored mailbox
Set-HVEAccountSettings -Identity hve-payroll@contoso.com -ReplyTo "payroll-team@contoso.com"If the tenant uses a federated domain, Microsoft documents creating the account with a federated-domain address directly, or switching it later with Set-MailUser -HVEAccount -Identity <address> -PrimarySmtpAddress <federated address>. The primary SMTP address can be changed only in PowerShell, not in the EAC.
Create one HVE account per application or environment. Separate accounts make the usage report easier to read and let you rotate one app's credentials without touching the others.
Step 3: Choose an authentication method
HVE supports basic authentication (account password) and OAuth. Microsoft recommends OAuth where the application supports it.
Before you choose, check your tenant settings:
- Security defaults in Microsoft Entra ID disable all basic authentication, including SMTP. With security defaults on, HVE accepts only OAuth.
- Authentication policies can block basic SMTP. If you use them, make sure the policy that applies to the HVE account has
AllowBasicAuthSmtpenabled. You can apply a custom authentication policy just to HVE accounts. SmtpClientAuthenticationDisabledinSet-TransportConfigdoesn't affect HVE, because HVE uses a dedicated endpoint.
Configure OAuth
- In the Microsoft Entra admin center, go to Identity > Applications > App registrations > New registration and register the application.
- Under API permissions, select Add a permission > APIs my organization uses, search for Office 365 Exchange Online and add Mail.Send:
- Application permission for apps that use a client secret. Add the secret under Certificates & secrets.
- Delegated permission for apps that sign in with the HVE account's own credentials. Also enable Allow public client flows on the Authentication tab.
- Select Grant admin consent.
- The application requests a token for the audience
https://outlook.office.com/.default.
Granting the application permission doesn't let the app send as every mail user. Microsoft states that with this configuration only HVE account mail users can send, unless you explicitly authorize the app for other mail users through application access policies or RBAC for Applications.
To prevent other applications from using a particular HVE account, add an allow list. You can list up to 10 applications per account. Use the service principal object ID from the Enterprise applications blade, not the object ID from App registrations:
Add-HVEAppAccess -Identity hve-payroll@contoso.com -AppIds 00000000-0000-0000-0000-000000000001
Get-HVEAccountSettings -Identity hve-payroll@contoso.com | Format-List *AllowedApps*Allowed applications apply to OAuth only. Basic authentication with the password isn't affected.
The client authenticates with the AUTH XOAUTH2 command, using this base64-encoded string (^A is the Control+A character):
base64("user=" + userName + "^Aauth=Bearer " + accessToken + "^A^A")Step 4: Configure the application or device
| Setting | Value |
|---|---|
| SMTP server (smart host) | smtp.hve.mx.microsoft (recommended); smtp-hve.office365.com will be deprecated |
| Port | 587 |
| TLS/StartTLS | Enabled |
| Authentication | HVE account credentials or OAuth token |
Use the smtp.hve.mx.microsoft host name for new configurations so you don't have to update devices again when the older name is retired.
Verify
- In the EAC, go to Mail flow > High Volume Email and confirm that the account shows a billing policy name and an Account status of Active.
- Send a test message from the application to an internal mailbox and confirm it arrives.
- In the EAC, go to Reports > Mail flow > High Volume Email. Choose a time period (7, 30 or 90 days, or a custom start date), switch between Recipient volume and Message volume, and select the account to see its usage next to the tenant total.
- In PowerShell, check the billing state:
Get-HVEAccountBillingPolicy -Identity hve-payroll@contoso.comA BillingPolicyStatus of BillingPolicyValid means the policy is assigned and the subscription is active.
Troubleshooting
Authentication errors
| Error | Cause and fix |
|---|---|
535 5.7.3 Authentication unsuccessful | Wrong credentials, or basic authentication is blocked. Check security defaults and the authentication policy that applies to the account. |
535 5.7.139 Authentication unsuccessful, the organization configuration doesn't allow this authentication request. | Basic authentication is blocked by tenant configuration. Microsoft's documented fix is to turn off security defaults or allow AllowBasicAuthSmtp in the applicable authentication policy. Moving the app to OAuth avoids the need to weaken either setting. |
501 5.5.121 to 501 5.5.126 | The XOAUTH2 string is malformed: not base64, wrong field order, or missing user, Bearer keyword or token. Rebuild it in the format shown above. |
535 5.7.142 / 535 5.7.143 | The token is about to expire or has expired. Request a new token, and keep SMTP sessions shorter than the token lifetime. |
535 5.7.144 | Invalid API permissions. Check that Mail.Send from Office 365 Exchange Online is granted with admin consent and that the permission type matches the token flow. |
550 5.7.240 | The application is not allowed for this HVE account. Add its service principal ID with Add-HVEAppAccess. |
Billing states
If an account shows Not active, read BillingPolicyStatus from Get-HVEAccountBillingPolicy:
| Status | Meaning |
|---|---|
NoProperBillingPolicyStored | No policy assigned. Assign one in the EAC or with Set-HVEAccountBillingPolicy. |
BillingPolicyNotFound | The assigned policy was deleted. |
BillingPolicyMismatched | The policy retrieved doesn't match the expected tenant or policy identity. Microsoft describes this as uncommon. |
NoConnectedBillingPolicyFound | The policy isn't connected to High Volume Email in Billing > Pay-as-you-go. |
SubscriptionIsNotActive | The Azure subscription behind the policy is inactive or deleted. |
NoSPOLicenseFound | The tenant has no SharePoint license, so the policy can't be validated. |
The device still can't send
Check the host name, port 587 and TLS on the device itself, and confirm that the credentials or token are valid. Microsoft also suggests testing the HVE account separately from the device with the SMTP connector in Power Automate. If that test works, the problem is on the device.
Checklist
- Pay-as-you-go billing policy created and connected to High Volume Email
- One HVE account per application, in an accepted domain, with no license assigned
- Billing policy assigned and account status Active
- Authentication chosen: OAuth with an allowed-applications list, or basic auth with security defaults and authentication policies checked
- Reply-To set where recipients may answer
- Devices pointed at
smtp.hve.mx.microsoft:587with TLS - Recipients batched to 50 per message or sent to a distribution list
- External recipients routed through another service
- HVE usage report reviewed after the first week
References
- Manage High Volume Email for Microsoft 365
- Use OAuth authentication for high volume emails for Microsoft 365
- Troubleshoot issues with high volume email for Microsoft 365
- Configure pay-as-you-go billing in the Billing node
- How to set up a multifunction device or application to send email using Microsoft 365
- Enable or disable SMTP AUTH in Exchange Online
- Updated Exchange Online SMTP AUTH Basic Authentication deprecation timeline
- Introducing Exchange Online Tenant Outbound Email Limits