Description
Microsoft Exchange Online Protection must be enabled for a domain in the Microsoft tenant to report as healthy. This presents a challenge for Shield partners and customers who do not wish to check the Microsoft Quarantine for held messages. Below are the steps that prevent inbound messages from being captured by Microsoft Quarantine.
Shield - Bypass Spam Filtering
By default, the Shield - Bypass Spam Filtering rule is created when Shield is deployed to a M365 tenant. This rule tells inbound messages sent via Shield to Microsoft that they should be skipped for evaluation by Microsoft Exchange Online Protection (EOP). The rule changes the Spam Confidence Level to -1 to bypass EOP spam filtering so that only Shield will evaluate the message for spam characteristics.
Shield MX Record
Pointing each Shield domain's MX record to Shield ensures inbound mail is delivered to Shield first. Shield performs spam, phishing, and threat evaluation, then relays accepted mail to the M365 tenant.
By default, there is no requirement to change the MX record that points to Microsoft to point to the Shield value instead. However, even when a message bypasses EOP spam filtering, the following protections are never bypassed:
- Malware scanning: Messages containing malware are always quarantined.
- High confidence phishing (HPHSH): Messages identified as high confidence phishing are always quarantined (unless the MX record doesn't point to Microsoft 365 and an SCL -1 rule is in place). Source: Microsoft
Setting the MX record to the Shield value will allow High Confidence Phishing to bypass EOP. We don’t require MX record changes. However, the only way to prevent mail Microsoft considers High Confidence Phishing from being quarantined in the M365 tenant is to use the Shield MX record.
The MX record value for Shield follows the pattern: domain-tld.in.shield.security
For example, the Shield MX record for:
- Domain mptestercody.com would be: mptestercody-com.in.shield.security
- Domain mptesterstef.net would be: mptesterstef-net.in.shield.security
- Domain mptestertilly.info would be: mptestertilly-info.in.shield.security
- Domain mptesterhildegard.biz would be mptesterhildegard-biz.in.shield.security
...and so on.
Please contact Support with any questions about the MX record for a Shield domain, as an incorrectly configured MX record will result in bounced mail.
Related to
Updated