Skip to main content

Creating a Connector in Exchange Admin Center

What a Connector Is. A connector in Microsoft Exchange is essentially a configured pathway that controls how mail flows into or out of your organization. It defines: Where mail comes from or goes to…

Meg Bird
Updated by Meg Bird

What a Connector Is

A connector in Microsoft Exchange is essentially a configured pathway that controls how mail flows into or out of your organization. It defines:

  • Where mail comes from or goes to (e.g. a specific IP range, a partner's mail server)
  • How the connection is authenticated (certificate-based, IP-based, or via a security identifier)
  • What transport security is required (e.g. enforced TLS)

There are two main types:

  • Inbound connectors: control mail coming into your Exchange environment
  • Outbound connectors: control mail leaving your environment

Why Connectors Benefit Email Delivery

  1. Reliable routing: They ensure mail from a known source (such as Boxphish) reaches your Exchange server instead of being routed unpredictably or rejected.
  2. Bypassing overly aggressive filtering for trusted sources: If you have a legitimate bulk-mail reason a connector ensures these emails aren’t accidentally caught by spam filtering meant for the open internet.
  3. Enforcing delivery standards with partners: For business-to-business mail flow, connectors can require TLS encryption in transit with a specific partner, improving deliverability confidence and reducing bounce/rejection issues.

Where Connector Responsibility Ends

This is the important distinction: a connector governs mail in transit;  authentication of the sending source and the transport security of the connection itself. It is not a content security or mailbox security control.

Once a message has arrived and been accepted:

  • Content filtering (anti-spam, anti-malware, safe attachments/links) is handled by separate systems, such as Exchange Online Protection (EOP), Defender for Office 365, or on-premise agents.
  • Mailbox-level security (access controls, encryption at rest, retention policies, conditional access) is governed by mailbox and tenant security settings, entirely separate from the connector.
  • A connector doesn't grant elevated trust to message content. It only affects how the connection is treated. A connector can make delivery more reliable without that mail skipping malware/phishing scanning.

In summary, connectors influence whether and how mail gets delivered, not what happens to it after arrival. Those are handled by distinct layers of Exchange/EOP security architecture.

How to add the Connector:

Please follow this guide if you have previously implemented the 'Boxphish Header Allow' rule in Exchange, and populated the Domains, Sending IPs and simulation URLs in Defender.

Before starting, please make sure you are a Global Administrator or have the required permissions to administer 365.

  1. Navigate to 365 Exchange https://admin.exchange.microsoft.com
  2. Expand the 'Mail Flow' tab on the left.
  3. Select 'Connectors'.
  4. Select 'Add Connector'.
  5. New connector:
    1. Select 'Partner organization' as the Connection from, then click Next.
  6. Connector name:
    1. Name the rule as you would like, for example 'Boxphish Trusted Connector'.
    2. Leave 'Turn it on' enabled, then click Next.
  7. Authenticating sent email:
    1. Select 'By verifying that the IP Address of the Sending Server matches…'
    2. Enter the IP Addresses detailed on the Boxphish portal HERE:
      1. Navigate to Settings > Deliverability > Sending Information:
      2. Select Sending IPs 'view'.
    3. Click Next.
  8. Security restrictions:
    1. Enable: 'Reject email messages if they aren't sent over TLS', click Next.
  9. Review connector:
    1. 'Create connection'.
  10. Confirm the connector has been created and is enabled, from the Connectors list.

Microsoft will activate it within a few minutes. You will then be able to send a simulation via On-Demand, to test this Connector.

If you have any issues or questions regarding adding the Connector, please get in touch with Boxphish Support on support@boxphish.com.

How did we do?

Email Protection Allow Listing

Contact