Office 365 SMTP Relay: Choose the Right Sending Method
Summarize with AI
For SMTP relay in Office 365, choose SMTP AUTH client submission when one application can authenticate as a licensed mailbox, Direct Send when a device only needs to reach recipients inside your tenant, and an Exchange Online connector when an on-premises system must send externally without a mailbox login. Microsoft classifies all three as sending methods. Only the relay path creates an inbound connector.
Compare the Three Microsoft 365 Sending Methods
The choice starts with recipient scope and authentication. The current Microsoft device and application sending guide documents the following boundaries.
| Decision | SMTP AUTH client submission | Direct Send | SMTP relay connector |
|---|---|---|---|
| Best fit | One app can authenticate as a mailbox | Legacy device sends internally only | On-premises system sends internally and externally |
| Server | `smtp.office365.com` | Tenant MX endpoint | Tenant MX endpoint |
| Port | 587 recommended | 25 | 25 |
| External recipients | Yes | No | Yes |
| Authentication | OAuth or legacy Basic Authentication | None | TLS certificate or dedicated static public IP |
| Sender mailbox | Licensed mailbox required | No mailbox required | No sender mailbox required |
| Sent Items copy | Yes | No | No |
Teams lose time when they configure Direct Send because it looks simple, then discover that an external supplier, customer, or alerting address cannot receive the message.
Use SMTP AUTH for One Accountable Application
SMTP AUTH client submission fits a CRM, scanner service, or business application that can authenticate as a dedicated Microsoft 365 mailbox. Configure smtp.office365.com, use port 587, require TLS, and use OAuth for a new integration.
Microsoft's SMTP AUTH administration guide recommends disabling SMTP AUTH across the organization and enabling it only for mailboxes that still need it. Microsoft Entra security defaults disable SMTP AUTH. That is a useful default because it turns the exception into an explicit decision rather than leaving every mailbox available for client submission.
If an application authenticates as one mailbox but places another mailbox in the From field, the authenticated account needs Send As permission. Without it, Exchange Online can reject the submission with 5.7.60.
Microsoft publishes a mailbox limit of 10,000 recipients in a rolling 24-hour period, up to 1,000 recipients per message, and 30 messages per minute in its Exchange Online limits. The published figures are service ceilings. They do not establish operating volume targets.
Plan for the End of Basic Authentication
Microsoft's updated SMTP AUTH timeline leaves Basic Authentication unchanged through December 2026. It is scheduled to become disabled by default for existing tenants at the end of December 2026, while administrators can still re-enable it. New tenants created after that point are expected to use OAuth by default.
Do not build a new username-and-password integration around that temporary window. Use OAuth where the application supports it. If a legacy device cannot, document the exception, the replacement date, and who will test the change.
Use Direct Send Only for Internal Recipients
Direct Send submits unauthenticated mail to your tenant's MX endpoint on port 25. The From address must use an accepted domain, but it does not need an Exchange Online mailbox. Microsoft 365 treats the connection as anonymous internet mail and applies the normal filtering for that traffic.
Direct Send can deliver only to recipients in your organization's accepted domains. It cannot use Microsoft 365 to relay to external recipients.
Microsoft says most customers do not need Direct Send and recommends it only when the other methods do not work.
Use an Exchange Online Connector for On-Premises Relay
An Office 365 SMTP relay connector fits an on-premises application, device, or mail server that must send internally and externally without authenticating as a licensed mailbox. It sends to the tenant's MX endpoint on port 25 and matches an inbound connector.
Microsoft recommends certificate authentication. The certificate Subject or Subject Alternative Name must contain a verified accepted domain, and the connection needs TLS 1.2 or 1.3. If certificate authentication is unavailable, the connector can match a dedicated static public IP visible to Microsoft 365. Dynamic addresses and public addresses shared with another organization do not meet that model.
The current Exchange Online relay requirements require two matches. An accepted domain must appear in the SMTP certificate domain or the envelope sender, and the source IP or certificate domain must match the connector. The visible From header alone does not satisfy the accepted-domain condition.
That envelope rule catches systems that display an approved From address while using a different MAIL FROM value. Test the real application, not a laptop imitation, and retain the SMTP conversation or application logs.
Check Limits, Retries, and Failure Evidence
A connector avoids SMTP AUTH's licensed-sender requirement and per-mailbox ceiling. Microsoft describes relay capacity as reasonable use and bars spam and bulk mail. Tenant-wide external-recipient limits can also count traffic relayed from on-premises systems.
Microsoft has published conflicting trial-tenant figures across current pages, so we would not copy one number into an operating policy. Check Exchange admin center > Reports > Mail flow > Tenant Outbound External Recipients Rate for the tenant's actual quota and enforcement state.
The sending application also needs retry logic for temporary failures. Save the connector name, certificate domain or source IP, envelope sender, timestamps, and SMTP responses. Our email authentication troubleshooting guide can help separate identity failures from a connector or transport failure.
Run a negative test after the positive tests. A source outside the approved IP range or certificate identity should fail. If both approved and unapproved sources can send, the connector is not finished.
Ready to Review Your Microsoft 365 Sending Path?
We can map the application, connector, authentication, retry, and ownership boundaries inside the outbound system your team controls. Review our services or book your free discovery call →.
Frequently Asked Questions
A strong positive reply rate for B2B cold email is 1.5–3%. Top-performing campaigns with tight targeting and personalized copy can hit 4–5%. If you're below 1%, it usually signals a deliverability or messaging problem, not a volume problem.
The safe range is 30–50 emails per inbox per day for warmed inboxes. That's why outbound systems use multiple inboxes (we use 80) to reach 40,000+ monthly sends while keeping each inbox well within safe limits. Sending more than 50/day from a single inbox risks spam folder placement.
Yes. The CAN-SPAM Act permits unsolicited commercial email as long as you include a physical address, an unsubscribe mechanism, accurate headers, and non-deceptive subject lines. Unlike GDPR in Europe, the US does not require prior opt-in consent for B2B cold outreach.
Domain warm-up typically takes 2–3 weeks. During this period, sending volume gradually increases while the email warm-up tool generates positive engagement signals (opens, replies) to build sender reputation. Skipping or rushing warm-up is the most common cause of deliverability problems.
Cold email is targeted, relevant outreach to a specific person based on their role, industry, or company, with a clear business reason. Spam is untargeted mass messaging with no personalization or relevance. The distinction matters legally (CAN-SPAM compliance) and practically (deliverability depends on relevance signals).

Dimitar Petkov
Co-Founder of LeadHaste. Builds outbound systems that compound. 4x founder, Smartlead Certified Partner, Clay Solutions Partner.


