Exchange Online

Microsoft’s MX Change in July26: A follow up on my DNSSEC and SMTP DANE articles

Microsoft has announced a significant change in how new Accepted Domains in Exchange Online are provisioned with MX records. Between early and late July 2026 (previously February), MS will gradually switch provisioning of all A records for new Accepted Domains into the new subdomains under mx.microsoft. *.mx.microsoft At first glance, this may look like a …

Cloud-managed Remote Mailboxes: What It Means for Your Business (and What You Can Do This Week)

Carrying out the last exchange server

Microsoft just introduced cloud-managed remote mailboxes for directory-synced users. In plain English: you can manage Exchange attributes for synced mailboxes directly in Exchange Online without keeping an on-prem Exchange server for recipient admin. This post explains what that means for your business, the most valuable use cases, when not to enable it, and a 7-step pilot you can run this week. If “the last Exchange server” has been blocking your roadmap, this is the feature that finally moves you past it.

Keeping Direct Send Safe: A Practical Guide for Microsoft 365 Admins

Attackers rarely miss an opportunity to twist a convenient feature into a phishing tool. Exchange Online’s Direct Send is the latest example: security researchers have documented campaigns that drop fake “internal” messages straight into corporate inboxes—no credentials required. Headlines warn that these messages “bypass SPF, DKIM and DMARC,” leaving IT teams wondering whether the standard …

How to Configure Azure Communication Services SMTP Relay

A Modern SMTP Relay for Post-Exchange Environments As more organizations retire their last on-premises Exchange server, and as Microsoft Defender for Office 365 introduces more aggressive email throttling, many customers are facing the challenge of finding a new reliable SMTP relay. Azure Communication Services (ACS) with Email capabilities is emerging as a modern, scalable alternative. …

Set Up Plus Addressing for Admin Notifications

Licensing Microsoft Entra administrator accounts for email is a common practice, but it introduces avoidable security risks. Privileged accounts should remain isolated from unnecessary communication channels to minimize vulnerabilities. This guide shows how to set up email notifications for admin accounts without assigning them a mailbox license. We’ll also include visual steps for enabling plus …

Understand Opportunistic TLS and Email Encryption: A Deep Dive into S/MIME, Purview Message Encryption, and Secure Email.

This entry is part 1 of 2 in the series Email encryption

Enhancing Email Security: Opportunistic TLS and Encryption Solutions In Part 1 of this series, we explored how SMTP DANE and DNSSEC collaborate to secure email communications in Exchange Online, ensuring authenticity and encryption between servers. In this follow-up, we focus on two critical components of email security: Opportunistic TLS and email encryption. Specifically, we’ll examine …

Boosting Email Security with SMTP DANE and DNSSEC: A Complete Guide

This entry is part 1 of 2 in the series Email encryption

Introduction to SMTP DANE and DNSSEC Securing email communication is critical in the modern digital landscape. SMTP DANE (DNS-based Authentication of Named Entities) and DNSSEC (Domain Name System Security Extensions) are two technologies that strengthen email security by protecting against DNS-based attacks and ensuring encrypted connections between mail servers. What is DNSSEC? DNSSEC enhances the …

Understand DMARC – and use it NOW.

What is DMARC DMARC, which stands for Domain-based Message Authentication, Reporting, and Conformance, is a crucial email authentication and anti-phishing technology designed to enhance the security of email communication. It helps organizations combat email fraud, phishing attacks, and unauthorized use of their domain names by allowing domain owners to specify policies for how their email …