Microsoft Exchange
Connecting MXGuard to Exchange Server 2016/2019 and Exchange Online.
Exchange Server (on-premises)
After changing your MX records to MXGuard's servers, configure Exchange to accept mail only from our IP addresses:
Create a Receive Connector
In the Exchange Admin Center → Mail flow → Receive connectors → New. Type: Internet. Name: "MXGuard".
Restrict to allowed IP addresses
In the "Remote IP ranges" field, remove the 0.0.0.0–255.255.255.255 range and add only our subnets:
88.198.102.232/2962.76.100.176/2962.76.113.32/27Set the target server in MXGuard
In the MXGuard panel → Domains → set your Exchange server's FQDN as the delivery target server.
Exchange Online (Microsoft 365)
For Exchange Online, the target server looks like company-com.mail.protection.outlook.com — you can find it in your domain's MX records before switching to MXGuard.
We also recommend configuring Enhanced Filtering for Connectors in the Security & Compliance Center, so Microsoft doesn't re-score mail that already passed our filter.
include:spf.mxguard.net, so Microsoft accepts mail from our IPs.