Set up outbound email handling with Exchange and other clients

This document guides you through the process of directing all outbound email via Sophos Email. For Exchange, this requires an SMTP Connector to be configured on your Exchange Server.

For help with Exchange see the following:

To set up outbound email handling, do as follows:

  1. To set up an SMTP connector, follow the instructions for your version of Exchange on Microsoft's website.
  2. When prompted, select Route mail through smart hosts and click + Add.
  3. In the Add smart host dialog that appears, enter the corresponding smart host for your region.
    1. To find the smarthost for your region, sign in to Sophos Central.
    2. Go to Email Gateway > Settings > Domain Settings > Configure External Dependencies.
    3. Click on the outbound settings tab. You will see the Outbound Relay Host associated with your account. (This will be dependent on the region you chose when you signed up for Sophos Email.)

    Region

    Outbound Relay Host

    United States (West)

    relay-us-west-2.prod.hydra.sophos.com

    United States (East)

    relay-us-east-2.prod.hydra.sophos.com

    Germany

    relay-eu-central-1.prod.hydra.sophos.com

    Ireland

    relay-eu-west-1.prod.hydra.sophos.com

  4. Turn off or remove any other Outbound Send Connectors that were previously used for mail filtering.
    Note Failure to do this means your outbound email will still use the older send connectors, and is not routed through Sophos Email. If in doubt, consult Sophos Support.

Updating the SPF record for your domain

If you authenticate outgoing email using an SPF record or DKIM, you may need to update your configuration.

Your organization should already have a SPF record for your domains registered with your existing email service. You need to update this record in the DNS zone for the relevant domain.

You can replace your existing SPF record or add to it, depending on your requirements.

It's normal to replace the record. However, if your outbound email is being routed through Sophos Email and your existing email service simultaneously for a period, you can add an include statement for Sophos Email to your existing SPF record.

You can use the all parameter in different ways. You must understand how to do this and the implications of your choice.

  • Hard fail:

    You can use a dash (-) before the all parameter for a hard fail. If your mail isn't sent from Sophos Email, and your recipients' mail servers carry out SPF checks, they'll reject your mail.

  • Soft fail:

    You can use a tilde (~) before the all parameter instead, for a soft fail. The command doesn't fail if an IP address doesn't exist, it continues and processes the rest of the IP addresses. If your recipients' mail servers carry out SPF checks, they won't reject your mail.

Warning You may get the error SPF PermError: too many DNS lookups after changing your SPF record. To solve this, use the specific domain for the Sophos datacenter for your region instead of _spf.prod.hydra.sophos.com.

For more details, see Prevent SPF PermError: too many DNS lookups

Replacing your SPF record

If your outbound email is only routed through Sophos Email you can use the Sophos Email SPF record.

  • Remove v=spf1 include:spf.protection.outlook.com –all.
  • If you're certain that you don't have any third parties sending mail on your behalf, and all your outbound mail is routed through Sophos Email, you can set your record to:

    v=spf1 include:_spf.prod.hydra.sophos.com -all

  • If you aren't routing all your email through us, or you're unsure, use a soft fail:

    v=spf1 include:_spf.prod.hydra.sophos.com ~all

Adding to your SPF record

If your outbound email is being routed through Sophos Email and your existing email service simultaneously for a period, you can leave the original SPF record, and add an include statement for Sophos Email.

To use an include statement to add the Sophos Email record to your existing record, do as follows:

Existing SPF: v=spf1 include:spf.protection.outlook.com -all

Example with include: SPF: v=spf1 include:spf.protection.outlook.com include:_spf.prod.hydra.sophos.com -all

We recommend you replace your include statement with the Sophos Email SPF record when all your outbound email is routed through us.

Confirm that outbound mail is flowing by sending an outbound mail to an external address.

To confirm that the email has been sent, do as follows:

  1. Sign in to Sophos Central.
  2. Go to Email Gateway > Logs and Reports > Message History.
  3. Change the direction to outbound.
  4. Refresh the screen until you can see the details of the test email you have sent.