G DATA 365 | Mail Protection

Why must a connector and a rule be created in Microsoft Exchange Online?

How attackers bypass cloud-based third-party security solutions

As soon as a domain has been added to and verified in your Microsoft Exchange Online, Microsoft assigns each tenant a default domain. Attackers know that the standard MX records for the onmicrosoft.com domains are typically "Firmenname.onmicrosoft.com".

Using the results of MX lookups for "Firmennamen.onmicrosoft.com", attackers can fill entire databases with information about whose email is hosted on Microsoft 365 and who has routed their MX record through third-party security software.

Based on these findings, email messages can then be sent directly to Microsoft Exchange Online, which Microsoft would also accept. This allows such an email gateway solution to be bypassed.

Using connectors and rules secures Microsoft Exchange Online against these bypasses and can eliminate the need to change the MX record.

Changing the MX record to a gateway is, as can be seen from the chapter "How attackers bypass cloud-based third-party security solutions", not sufficient.

In addition, the simplified DNS setup provided by Microsoft for Microsoft Exchange Online cannot be used with custom DNS routing. For experienced users who manage their own DNS, changing the MX record in addition is usually straightforward; for less experienced users, it can result in complicated additional work. Further information on this topic can be found in our chapter Set your domain’s MX record to G DATA 365 | Mail Protection

The inbound connector

For smooth mail flow, it is necessary to create a dedicated inbound connector. Because Microsoft uses the greylisting method and G DATA 365 | Mail Protection uses different sender IP addresses, unnecessary delays in mail receipt may otherwise occur.

Conclusion

To ensure that G DATA 365 | Mail Protection cannot be bypassed and that no receipt issues occur due to greylisting, it is absolutely necessary to create the partner connectors (inbound and outbound) as well as a rule.

Enter all domains that are to be monitored by G DATA 365 | Mail Protection. The result is that all email messages for the domains entered in the rule that arrive from external sources are first forwarded to G DATA 365 | Mail Protection. Microsoft Exchange Online accepts only email messages that are delivered to it after being checked by G DATA 365 | Mail Protection.

If certain points are observed, changing the MX record is no longer necessary, but it can be done if desired.