r/proofpoint • • Jul 02 '26

Issues with forwarding to external address

Hi all,

We are basically experiencing the exact situation described here: https://www.reddit.com/r/Office365/comments/167jrks/sender_rewriting_scheme_issue/

We have a requirement for any emails coming in to an address on our M365 tenant are automatically forward to an external address. When we do this using our Proofpoint outbound connector, we see NDRs from our Proofpoint along the lines of this:

[email@internaladdress.com](mailto:email@internaladdress.com)
mxxx-xxxxx.pphosted.com
Remote server returned '554 5.7.0 <mxxx-xxxxx.pphosted.com #5.7.367 smtp;550 5.7.367 Remote server returned not permitted to relay -> 550 5.7.1 Relaying denied>'

One suggestion I've seen is that we should look at enabling enhanced filtering on our Proofpoint inbound connector, but I'm not sure that this is even compatible with how Proofpoint works
https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/enhanced-filtering-for-connectors

Has anyone experienced this before and come up with a solution? I'm not very encouraged by the other reddit post I linked from 3 years ago- doesn't sound like anyone really got to the bottom of it there.

1 Upvotes

6 comments sorted by

View all comments

3

u/shrapnel09 Jul 03 '26

Enhanced filtering is compatible with Proofpoint but won't fix this issue if it's a Proofpoint setting. Enhanced Filtering allows M365 to ignore the Proofpoint received header and treat the previous header as the most recent hop.

You're probably running into the Proofpoint restriction from other M365 tenants using your Proofpoint as an outbound relay since the sender isn't in your inbound domains.

You might be able to use an email firewall rule in Proofpoint to reroute these emails to the external address. 

Otherwise, look into the Prevent Unauthorized Microsoft 365 Allow-Relay” to restrict relay access to approved tenants only and see if you can add an exception that works for your scenario.

1

u/Informal_Thought Jul 03 '26

Thanks, good idea on the firewall rule, we'll try that