To send mail from printers, scanners and line-of-business apps through Microsoft 365, use SMTP AUTH (smtp.office365.com:587 with a mailbox, preferably over OAuth) when the device must reach external recipients and can authenticate. Use an SMTP relay connector (your MX endpoint on port 25, authenticated by certificate or static IP) when it can't authenticate but must still reach the internet. Direct Send and High Volume Email reach only your own mailboxes. Azure Communication Services Email is the alternative Microsoft recommends for application mail to internal and external recipients, and for high-volume sending, now that SMTP AUTH Basic authentication is being switched off by default at the end of December 2026.
Who this is for and what you will have
This guide is for Microsoft 365 and Exchange Online administrators who need to keep scan-to-email, alerting, ticketing and other application mail working. These senders often have to change at the same time as two security changes: the end of default SMTP AUTH Basic authentication, and the option to reject unauthenticated Direct Send.
At the end you will have:
- A comparison of the five supported sending methods, with their settings, limits and authentication.
- A way to choose a method for each device or application.
- Configuration steps for SMTP AUTH, a relay connector and Direct Send, plus pointers for HVE and Azure Communication Services.
- The error messages each method produces and how to fix them.
The five options at a glance
Microsoft documents four methods inside Exchange Online and recommends Azure Communication Services (ACS) Email as the fifth for external mail:
| SMTP AUTH (client submission) | SMTP relay connector | Direct Send | High Volume Email | ACS Email (SMTP) | |
|---|---|---|---|---|---|
| Endpoint | smtp.office365.com | Your MX endpoint, for example contoso-com.mail.protection.outlook.com | Your MX endpoint | smtp.hve.mx.microsoft | smtp.azurecomm.net |
| Port | 587 (recommended) or 25 | 25 | 25 | 587 | 587 (recommended) or 25 |
| TLS | Required (1.2 or 1.3) | Optional (enabled in Microsoft's setup tables) | Optional | Required | Required (1.2 or later) |
| Authentication | Mailbox credentials or OAuth | Certificate or static public IP on an inbound connector | None | HVE account password or OAuth | SMTP username plus Entra app client secret |
| External recipients | Yes | Yes | No | No | Yes |
| Third-party hosted apps | Yes | No | Yes | Yes | Yes |
| Licensed mailbox needed | Yes | No | No | No (pay-as-you-go) | No (Azure billing) |
| Saves to Sent Items | Yes | No | No | No | No |
| Throttling | 10,000 recipients per day, 30 messages per minute | "Reasonable limits"; no spam or bulk mail | Standard throttling for anonymous internet mail | No recipient or message rate limits | ACS Email service limits |
Two rows are easy to miss. A relay connector can't be used for an app hosted in a third-party cloud such as Azure, because the connector trusts a certificate or IP that belongs to your organization. And Direct Send and HVE both deliver only inside your tenant.
How to choose
Work through these questions for each sender:
- Does it only email your own staff? Use High Volume Email if it can do TLS on port 587 and authenticate. HVE has no rate limits, needs no license and accepts OAuth. See High Volume Email for Microsoft 365. Use Direct Send only if the device can't authenticate at all.
- Does it need to reach external recipients in low volumes, and can it use OAuth? Use SMTP AUTH with OAuth from a licensed mailbox.
- Does it need external recipients but can't authenticate? Use a relay connector if it sends from your own network with a static public IP or a certificate. Otherwise route it through an on-premises Exchange server or another relay.
- Is it a hosted application sending to customers, or does it send in bulk? Use ACS Email. Microsoft's outbound sending limits guidance lists it as a Microsoft service purpose-built for high-volume email, and Microsoft's Exchange Team FAQ confirms that ACS messages don't count against the tenant external recipient quota.
The volume question matters because all mail that leaves Exchange Online to external addresses counts against the tenant-wide quota described in Tenant External Recipient Rate Limit (TERRL).
Option 1: SMTP AUTH (client submission)
The device signs in as a mailbox and sends through smtp.office365.com. The mailbox address appears as the sender.
Requirements
- A licensed Exchange Online mailbox.
- TLS 1.2 or 1.3. If the device only offers port 465, it doesn't support the TLS versions Microsoft requires.
- SMTP AUTH enabled for that mailbox. It's disabled for organizations created after January 2020, and security defaults also turn it off.
Configure
# Check the organization-wide setting (True = disabled)
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
# Keep it disabled for the org, enable it only for the device mailbox
Set-CASMailbox -Identity scanner@contoso.com -SmtpClientAuthenticationDisabled $false
# Verify (False = enabled, blank = follows the org setting)
Get-CASMailbox -Identity scanner@contoso.com | Format-List SmtpClientAuthenticationDisabledThen set the device to smtp.office365.com, port 587, STARTTLS on, and the mailbox's credentials. Use the host name, not an IP address.
The Basic authentication timeline
Microsoft's updated timeline, published January 27, 2026, replaced the earlier plan to start rejecting Basic authentication submissions on March 1, 2026 and reach 100% rejection on April 30, 2026:
| When | What happens |
|---|---|
| Now to December 2026 | SMTP AUTH Basic authentication behavior is unchanged |
| End of December 2026 | Basic authentication disabled by default for existing tenants; admins can still enable it |
| New tenants created after December 2026 | Basic authentication unavailable by default; OAuth is the supported method |
| Second half of 2027 | Microsoft announces the final removal date |
For devices that can't do OAuth, Microsoft's alternatives are HVE for internal recipients, ACS Email for internal and external recipients, or an on-premises mail server that accepts Basic authentication or anonymous relay. To find which senders still use Basic authentication, use the SMTP AUTH Clients Submission report in the Exchange admin center. The Exchange Team's original retirement announcement states that this report shows whether Basic auth or OAuth is used to submit each message.
Option 2: SMTP relay through an inbound connector
The device connects to your MX endpoint on port 25 and Exchange Online recognizes it through an inbound connector. It can send as any address in an accepted domain, including one with no mailbox, such as do_not_reply@contoso.com.
Find the MX endpoint in the Microsoft 365 admin center under Settings > Domains. Select the domain, open the DNS records tab and copy the MX Points to address or value. The domain status must be Healthy.
Create the connector
- In the Exchange admin center, go to Mail flow > Connectors and select Add a connector.
- Connection from: Your organization's email server. Connection to is set to Office 365 automatically.
- Name the connector, keep Turn it on selected and leave Retain internal Exchange email headers cleared.
- On Authenticating sent email, choose one:
- Certificate (recommended): verify that the subject name on the certificate matches a domain you enter, for example
contoso.com. That domain must be an accepted domain and appear in the certificate's Subject or SAN. If the certificate covers several hosts, Microsoft recommends*.contoso.com. - IP address: enter the static public IP address of the device or app server. Dynamic IPs aren't supported, and the IP mustn't be shared with other organizations.
- Certificate (recommended): verify that the subject name on the certificate matches a domain you enter, for example
- Review and select Create connector.
- Add the sending IP address to the domain's SPF record so recipients don't treat the mail as spam.
If you already run hybrid Exchange, the Hybrid Configuration Wizard connector may already cover this. Check that it uses *.contoso.com rather than a host name that isn't a registered domain in Microsoft 365.
The relay method has trade-offs: a spam blocklist entry on your IP disrupts mail, and the device must retry failed connections itself. Microsoft notes that client submission can work better for a device that isn't a full mail server.
Option 3: Direct Send
The device acts as an anonymous internet mail server and delivers straight to your MX endpoint on port 25. Exchange Online doesn't need any configuration, but Microsoft recommends Direct Send only for administrators who can take on mail-server responsibilities. Configure SPF with a static IP, plus DKIM and DMARC for the domain.
Direct Send messages go through all the scanning that internet mail gets, can't reach external recipients, and are subject to standard throttling for anonymous mail.
Reject Direct Send
Because unauthenticated mail that uses your own domain is a spoofing risk, Exchange Online has an opt-in organization setting that is off by default:
Set-OrganizationConfig -RejectDirectSend $true
# Confirm
Get-OrganizationConfig | Format-List RejectDirectSendWhen it's on, Exchange Online rejects anonymous messages to your mailboxes when the envelope sender (P1 MAIL FROM) domain is one of your accepted domains and the message doesn't match an inbound connector that checks the sender IP or certificate. The header From address isn't checked. Subdomains are also affected if the accepted domain has Accept mail for all subdomains enabled. The change takes up to 30 minutes to propagate, and you need the Organization Configuration role to change it. The Exchange Team has also said it plans to turn this on by default for new tenants.
Before you enable it, find your Direct Send senders. The Exchange Team suggests starting with the IP addresses and services listed in your domain's SPF record, and the Change Optics report in the Exchange admin center shows example Direct Send messages that the setting would affect. Then give each legitimate sender a partner inbound connector, preferably certificate-based, or move it to HVE or SMTP AUTH.
To confirm that a partner's test message now matches its connector:
Get-MessageTraceV2 -MessageId "<message-id>" | Get-MessageTraceDetailV2 | Format-ListOption 4 and 5: High Volume Email and ACS Email
HVE is the replacement for Basic-auth SMTP from internal-only senders. You create an HVE account, connect a pay-as-you-go billing policy and send to smtp.hve.mx.microsoft:587. The full procedure is in High Volume Email for Microsoft 365.
ACS Email covers external and bulk application mail:
- Create an Email Communication Services resource with a provisioned domain (Azure-managed or your own verified domain), and connect it to a Communication Services resource.
- Register a Microsoft Entra application and create a client secret.
- On the Communication Services resource, open Access control (IAM) and assign the app the Communication and Email Service Owner role. Alternatively, assign a custom role with
Microsoft.Communication/CommunicationServices/Read,Microsoft.Communication/CommunicationServices/WriteandMicrosoft.Communication/EmailServices/write. - Open SMTP Usernames, select Add SMTP Username and link it to the app. Wait until the status is Ready to use.
- Configure the device with
smtp.azurecomm.net, port 587, STARTTLS, the SMTP username, and the client secret as the password.
Troubleshooting
| Symptom or error | Likely cause | Fix |
|---|---|---|
5.7.60 SMTP; Client doesn't have permissions to send as this sender. | SMTP AUTH sign-in account differs from the From address | Grant Send As on the sending mailbox, or make the From address match the sign-in account |
550 5.7.68 TenantInboundAttribution; Direct Send not allowed for this organization from unauthorized sources | RejectDirectSend is on and the sender matched no connector | Create a partner inbound connector (certificate or IP) or move the sender to an authenticated method |
| SMTP AUTH fails for one mailbox only | Per-mailbox SmtpClientAuthenticationDisabled is True | Set it to $false for that mailbox |
| SMTP AUTH fails for everyone | Security defaults on, or an authentication policy blocks basic SMTP | Move the device to OAuth, HVE or ACS rather than weakening tenant security |
| Device defaults to port 465 | Device doesn't support the required TLS | Use 587 if available; otherwise use a relay connector or an on-premises relay |
| Relay or Direct Send mail lands in Junk | No SPF entry for the sending IP | Add the IP to SPF; configure DKIM and DMARC |
Bounces with 550 5.7.233 | Tenant external recipient quota exceeded | See Tenant External Recipient Rate Limit (TERRL) |
Microsoft also provides an automated diagnostic in the Microsoft 365 admin center for setting up or troubleshooting devices that send email. It requires a Microsoft 365 administrator account.
Summary
- Internal only, can authenticate: High Volume Email.
- Internal only, can't authenticate: Direct Send, with SPF, DKIM and DMARC. Plan for
RejectDirectSend. - External, low volume, can do OAuth: SMTP AUTH with OAuth.
- External, can't authenticate, on your network: relay connector with a certificate or static IP.
- External, hosted or bulk: Azure Communication Services Email.
- Before the end of December 2026: find every SMTP AUTH sender that still uses Basic authentication and move it.
References
- How to set up a multifunction device or application to send email using Microsoft 365 or Office 365
- Enable or disable SMTP AUTH in Exchange Online
- Updated Exchange Online SMTP AUTH Basic Authentication deprecation timeline
- Exchange Online to retire Basic auth for Client Submission (SMTP AUTH)
- Introducing more control over Direct Send in Exchange Online
- Set-OrganizationConfig: RejectDirectSend
- Manage High Volume Email for Microsoft 365
- Email SMTP support in Azure Communication Services
- Set up SMTP authentication for sending emails with Azure Communication Services
- Exchange Online limits: sending limits
- Troubleshoot outbound sending limits in Exchange Online
- Introducing Exchange Online Tenant Outbound Email Limits