Microsoft 365

SMTP AUTH vs Direct Send vs relay connector: sending mail from devices

Compare SMTP AUTH, Direct Send, an SMTP relay connector, High Volume Email and Azure Communication Services, and pick the right way for printers and apps to send through Microsoft 365.

11 min read
On this page

To send mail from printers, scanners and line-of-business apps through Microsoft 365, use SMTP AUTH (smtp.office365.com:587 with a mailbox, preferably over OAuth) when the device must reach external recipients and can authenticate. Use an SMTP relay connector (your MX endpoint on port 25, authenticated by certificate or static IP) when it can't authenticate but must still reach the internet. Direct Send and High Volume Email reach only your own mailboxes. Azure Communication Services Email is the alternative Microsoft recommends for application mail to internal and external recipients, and for high-volume sending, now that SMTP AUTH Basic authentication is being switched off by default at the end of December 2026.

Who this is for and what you will have

This guide is for Microsoft 365 and Exchange Online administrators who need to keep scan-to-email, alerting, ticketing and other application mail working. These senders often have to change at the same time as two security changes: the end of default SMTP AUTH Basic authentication, and the option to reject unauthenticated Direct Send.

At the end you will have:

  • A comparison of the five supported sending methods, with their settings, limits and authentication.
  • A way to choose a method for each device or application.
  • Configuration steps for SMTP AUTH, a relay connector and Direct Send, plus pointers for HVE and Azure Communication Services.
  • The error messages each method produces and how to fix them.

The five options at a glance

Microsoft documents four methods inside Exchange Online and recommends Azure Communication Services (ACS) Email as the fifth for external mail:

SMTP AUTH (client submission)SMTP relay connectorDirect SendHigh Volume EmailACS Email (SMTP)
Endpointsmtp.office365.comYour MX endpoint, for example contoso-com.mail.protection.outlook.comYour MX endpointsmtp.hve.mx.microsoftsmtp.azurecomm.net
Port587 (recommended) or 252525587587 (recommended) or 25
TLSRequired (1.2 or 1.3)Optional (enabled in Microsoft's setup tables)OptionalRequiredRequired (1.2 or later)
AuthenticationMailbox credentials or OAuthCertificate or static public IP on an inbound connectorNoneHVE account password or OAuthSMTP username plus Entra app client secret
External recipientsYesYesNoNoYes
Third-party hosted appsYesNoYesYesYes
Licensed mailbox neededYesNoNoNo (pay-as-you-go)No (Azure billing)
Saves to Sent ItemsYesNoNoNoNo
Throttling10,000 recipients per day, 30 messages per minute"Reasonable limits"; no spam or bulk mailStandard throttling for anonymous internet mailNo recipient or message rate limitsACS Email service limits

Two rows are easy to miss. A relay connector can't be used for an app hosted in a third-party cloud such as Azure, because the connector trusts a certificate or IP that belongs to your organization. And Direct Send and HVE both deliver only inside your tenant.

How to choose

Work through these questions for each sender:

  1. Does it only email your own staff? Use High Volume Email if it can do TLS on port 587 and authenticate. HVE has no rate limits, needs no license and accepts OAuth. See High Volume Email for Microsoft 365. Use Direct Send only if the device can't authenticate at all.
  2. Does it need to reach external recipients in low volumes, and can it use OAuth? Use SMTP AUTH with OAuth from a licensed mailbox.
  3. Does it need external recipients but can't authenticate? Use a relay connector if it sends from your own network with a static public IP or a certificate. Otherwise route it through an on-premises Exchange server or another relay.
  4. Is it a hosted application sending to customers, or does it send in bulk? Use ACS Email. Microsoft's outbound sending limits guidance lists it as a Microsoft service purpose-built for high-volume email, and Microsoft's Exchange Team FAQ confirms that ACS messages don't count against the tenant external recipient quota.

The volume question matters because all mail that leaves Exchange Online to external addresses counts against the tenant-wide quota described in Tenant External Recipient Rate Limit (TERRL).

Option 1: SMTP AUTH (client submission)

The device signs in as a mailbox and sends through smtp.office365.com. The mailbox address appears as the sender.

Requirements

  • A licensed Exchange Online mailbox.
  • TLS 1.2 or 1.3. If the device only offers port 465, it doesn't support the TLS versions Microsoft requires.
  • SMTP AUTH enabled for that mailbox. It's disabled for organizations created after January 2020, and security defaults also turn it off.

Configure

# Check the organization-wide setting (True = disabled)
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
 
# Keep it disabled for the org, enable it only for the device mailbox
Set-CASMailbox -Identity scanner@contoso.com -SmtpClientAuthenticationDisabled $false
 
# Verify (False = enabled, blank = follows the org setting)
Get-CASMailbox -Identity scanner@contoso.com | Format-List SmtpClientAuthenticationDisabled

Then set the device to smtp.office365.com, port 587, STARTTLS on, and the mailbox's credentials. Use the host name, not an IP address.

The Basic authentication timeline

Microsoft's updated timeline, published January 27, 2026, replaced the earlier plan to start rejecting Basic authentication submissions on March 1, 2026 and reach 100% rejection on April 30, 2026:

WhenWhat happens
Now to December 2026SMTP AUTH Basic authentication behavior is unchanged
End of December 2026Basic authentication disabled by default for existing tenants; admins can still enable it
New tenants created after December 2026Basic authentication unavailable by default; OAuth is the supported method
Second half of 2027Microsoft announces the final removal date

For devices that can't do OAuth, Microsoft's alternatives are HVE for internal recipients, ACS Email for internal and external recipients, or an on-premises mail server that accepts Basic authentication or anonymous relay. To find which senders still use Basic authentication, use the SMTP AUTH Clients Submission report in the Exchange admin center. The Exchange Team's original retirement announcement states that this report shows whether Basic auth or OAuth is used to submit each message.

Option 2: SMTP relay through an inbound connector

The device connects to your MX endpoint on port 25 and Exchange Online recognizes it through an inbound connector. It can send as any address in an accepted domain, including one with no mailbox, such as do_not_reply@contoso.com.

Find the MX endpoint in the Microsoft 365 admin center under Settings > Domains. Select the domain, open the DNS records tab and copy the MX Points to address or value. The domain status must be Healthy.

Create the connector

  1. In the Exchange admin center, go to Mail flow > Connectors and select Add a connector.
  2. Connection from: Your organization's email server. Connection to is set to Office 365 automatically.
  3. Name the connector, keep Turn it on selected and leave Retain internal Exchange email headers cleared.
  4. On Authenticating sent email, choose one:
    • Certificate (recommended): verify that the subject name on the certificate matches a domain you enter, for example contoso.com. That domain must be an accepted domain and appear in the certificate's Subject or SAN. If the certificate covers several hosts, Microsoft recommends *.contoso.com.
    • IP address: enter the static public IP address of the device or app server. Dynamic IPs aren't supported, and the IP mustn't be shared with other organizations.
  5. Review and select Create connector.
  6. Add the sending IP address to the domain's SPF record so recipients don't treat the mail as spam.

If you already run hybrid Exchange, the Hybrid Configuration Wizard connector may already cover this. Check that it uses *.contoso.com rather than a host name that isn't a registered domain in Microsoft 365.

The relay method has trade-offs: a spam blocklist entry on your IP disrupts mail, and the device must retry failed connections itself. Microsoft notes that client submission can work better for a device that isn't a full mail server.

Option 3: Direct Send

The device acts as an anonymous internet mail server and delivers straight to your MX endpoint on port 25. Exchange Online doesn't need any configuration, but Microsoft recommends Direct Send only for administrators who can take on mail-server responsibilities. Configure SPF with a static IP, plus DKIM and DMARC for the domain.

Direct Send messages go through all the scanning that internet mail gets, can't reach external recipients, and are subject to standard throttling for anonymous mail.

Reject Direct Send

Because unauthenticated mail that uses your own domain is a spoofing risk, Exchange Online has an opt-in organization setting that is off by default:

Set-OrganizationConfig -RejectDirectSend $true
 
# Confirm
Get-OrganizationConfig | Format-List RejectDirectSend

When it's on, Exchange Online rejects anonymous messages to your mailboxes when the envelope sender (P1 MAIL FROM) domain is one of your accepted domains and the message doesn't match an inbound connector that checks the sender IP or certificate. The header From address isn't checked. Subdomains are also affected if the accepted domain has Accept mail for all subdomains enabled. The change takes up to 30 minutes to propagate, and you need the Organization Configuration role to change it. The Exchange Team has also said it plans to turn this on by default for new tenants.

Before you enable it, find your Direct Send senders. The Exchange Team suggests starting with the IP addresses and services listed in your domain's SPF record, and the Change Optics report in the Exchange admin center shows example Direct Send messages that the setting would affect. Then give each legitimate sender a partner inbound connector, preferably certificate-based, or move it to HVE or SMTP AUTH.

To confirm that a partner's test message now matches its connector:

Get-MessageTraceV2 -MessageId "<message-id>" | Get-MessageTraceDetailV2 | Format-List

Option 4 and 5: High Volume Email and ACS Email

HVE is the replacement for Basic-auth SMTP from internal-only senders. You create an HVE account, connect a pay-as-you-go billing policy and send to smtp.hve.mx.microsoft:587. The full procedure is in High Volume Email for Microsoft 365.

ACS Email covers external and bulk application mail:

  1. Create an Email Communication Services resource with a provisioned domain (Azure-managed or your own verified domain), and connect it to a Communication Services resource.
  2. Register a Microsoft Entra application and create a client secret.
  3. On the Communication Services resource, open Access control (IAM) and assign the app the Communication and Email Service Owner role. Alternatively, assign a custom role with Microsoft.Communication/CommunicationServices/Read, Microsoft.Communication/CommunicationServices/Write and Microsoft.Communication/EmailServices/write.
  4. Open SMTP Usernames, select Add SMTP Username and link it to the app. Wait until the status is Ready to use.
  5. Configure the device with smtp.azurecomm.net, port 587, STARTTLS, the SMTP username, and the client secret as the password.

Troubleshooting

Symptom or errorLikely causeFix
5.7.60 SMTP; Client doesn't have permissions to send as this sender.SMTP AUTH sign-in account differs from the From addressGrant Send As on the sending mailbox, or make the From address match the sign-in account
550 5.7.68 TenantInboundAttribution; Direct Send not allowed for this organization from unauthorized sourcesRejectDirectSend is on and the sender matched no connectorCreate a partner inbound connector (certificate or IP) or move the sender to an authenticated method
SMTP AUTH fails for one mailbox onlyPer-mailbox SmtpClientAuthenticationDisabled is TrueSet it to $false for that mailbox
SMTP AUTH fails for everyoneSecurity defaults on, or an authentication policy blocks basic SMTPMove the device to OAuth, HVE or ACS rather than weakening tenant security
Device defaults to port 465Device doesn't support the required TLSUse 587 if available; otherwise use a relay connector or an on-premises relay
Relay or Direct Send mail lands in JunkNo SPF entry for the sending IPAdd the IP to SPF; configure DKIM and DMARC
Bounces with 550 5.7.233Tenant external recipient quota exceededSee Tenant External Recipient Rate Limit (TERRL)

Microsoft also provides an automated diagnostic in the Microsoft 365 admin center for setting up or troubleshooting devices that send email. It requires a Microsoft 365 administrator account.

Summary

  • Internal only, can authenticate: High Volume Email.
  • Internal only, can't authenticate: Direct Send, with SPF, DKIM and DMARC. Plan for RejectDirectSend.
  • External, low volume, can do OAuth: SMTP AUTH with OAuth.
  • External, can't authenticate, on your network: relay connector with a certificate or static IP.
  • External, hosted or bulk: Azure Communication Services Email.
  • Before the end of December 2026: find every SMTP AUTH sender that still uses Basic authentication and move it.

References

Questions people ask

Is SMTP AUTH being turned off in Exchange Online?

Basic authentication for SMTP AUTH is. Microsoft's January 2026 timeline keeps behavior unchanged until December 2026, then disables Basic authentication by default for existing tenants at the end of December 2026, with admins still able to turn it back on. The final removal date is due to be announced in the second half of 2027. SMTP AUTH with OAuth isn't affected.

Can Direct Send deliver to Gmail or other external addresses?

No. Direct Send connects to your tenant's MX endpoint as an anonymous sender, so it can deliver only to mailboxes in your Microsoft 365 organization. Messages to recipients outside the organization are rejected. Use SMTP AUTH, a relay connector or Azure Communication Services Email for external recipients.

What does 550 5.7.68 TenantInboundAttribution mean?

Your tenant has RejectDirectSend set to True, and an anonymous message using one of your accepted domains as the envelope sender didn't match any inbound connector. Create a partner inbound connector that matches the sender's certificate or IP address, or move the sender to an authenticated method.

Why can't I use port 465 for Microsoft 365 SMTP?

Microsoft's documentation states that a device or application that recommends or defaults to port 465 doesn't support the TLS versions that client SMTP submission requires. Use port 587 (recommended) or 25 with STARTTLS and TLS 1.2 or later.

Exchange OnlineSMTP AUTHDirect SendConnectorsAzure Communication Services
  1. Reject Direct Send in Exchange Online without breaking printers and apps

    Block spoofed Direct Send mail with RejectDirectSend while keeping approved printers, apps and SaaS senders working through partner inbound connectors.

    Microsoft 36511 min read
  2. Configure ARC trusted sealers and Enhanced Filtering for an email gateway

    Stop SPF, DKIM and DMARC failures on mail that reaches Exchange Online through a third-party gateway by combining Enhanced Filtering for Connectors and ARC.

    Microsoft 36511 min read
  3. Exchange Online connectors explained: inbound, outbound and partner setups

    Know when Exchange Online needs a connector, then build partner, gateway and on-premises connectors with forced TLS, IP or certificate restrictions and validation.

    Microsoft 36513 min read