EN FR
Features How it works Pricing Contact Login
🕒 Last updated: September 6, 2026

Set up Microsoft 365 to work with Clean Mailbox as your inbound gateway

A step-by-step guide to whitelist Clean Mailbox as a trusted source in Microsoft 365 / Exchange Online, and avoid delivery issues caused by SPF and DMARC.

⚠️

Microsoft 365's admin interfaces change regularly: the menus, labels and locations described below may differ from what you see today. This guide is provided as a courtesy to help you; it does not replace Microsoft's own official support, which remains solely responsible for guiding its customers through the administration of their Microsoft 365 tenant.

Why this is needed

When Microsoft 365 (Exchange Online) receives an email relayed by Clean Mailbox, it sees the IP address of our servers instead of the original sender's IP. If the sending domain enforces a strict SPF record (-all) and a strict DMARC policy (p=quarantine or p=reject), Microsoft may treat the email as unauthenticated — since Clean Mailbox's IP is not listed in the sender's SPF record — and block or quarantine it, even though it fully passed our own anti-spam and anti-malware filters.

This is expected behavior from Microsoft 365, not a malfunction of Clean Mailbox: relaying email on your behalf is exactly what an inbound security gateway does (Clean Mailbox, as well as Proofpoint, Mimecast or Barracuda), and it needs to be declared as a trusted source on the Microsoft 365 side.

This guide is intended for the domain administrator (or your IT provider) and covers a configuration you only need to perform once, after pointing your MX records to Clean Mailbox.

💡

This guide applies to domains whose mailboxes are hosted on Microsoft 365 / Exchange Online and protected on the inbound side by Clean Mailbox. If you're troubleshooting a one-off delivery failure, also check the non-delivery report (NDR) received by the sender — it usually points directly to the cause of the block.

IP addresses to allow

Clean Mailbox relays your incoming email from the following addresses. You'll need them for both steps below.

TypeAddresses
IPv4 213.32.76.196/32
51.178.81.41/32
45.63.114.93/32
163.172.164.47/32
IPv6 2001:41d0:404:200::4d8f/128
2001:41d0:302:1000::500/128
2001:19f0:6801:10c:5400:ff:fe58:b68/128
2001:bc8:710:a30:dc00:ff:fe8a:301/128
⚠️

This list may change as Clean Mailbox's infrastructure evolves. Before applying this configuration, check the up-to-date list from your customer portal, or confirm with us at [email protected].

1

Allow Clean Mailbox in the connection filter

This first step tells Microsoft 365's built-in anti-spam protection (Microsoft Defender) to treat our servers as a trusted source.

1. Open the Microsoft Defender security center

From the Microsoft 365 admin center, open All admin centers, then click Security.

Microsoft 365 admin center - accessing the security center
All admin centers → Security (shown here in French: "Tous les centres d'administration" → "Sécurité")

2. Go to anti-spam policies

In the Microsoft Defender left-hand menu, go to Email & collaboration → Policies & rules, then open Threat policies.

Microsoft Defender - Policies and rules
Microsoft Defender → Policies & rules (shown here in French: "Stratégies et règles")

3. Open Anti-spam

In the list of policies, click Anti-spam.

Threat policies - Anti-spam
Threat policies → Anti-spam (shown here in French: "Logiciel anti-courrier indésirable")

4. Open the connection filter policy

On the Anti-spam policies page, click Connection filter policy (Default).

Anti-spam policies - Connection filter policy
Anti-spam policies → Connection filter policy (Default) (shown here in French)

5. Add Clean Mailbox's IPs to the allow list

In the Always allow messages from the following IP addresses or address range field, add the IPv4 addresses listed above (one at a time, in x.x.x.x/32 format), check Turn on safe list, then click Save.

Connection filter policy - adding Clean Mailbox's IPs
Adding Clean Mailbox's IP addresses to the allow list
ℹ️

Microsoft 365 only accepts IPv4 addresses in this field. Clean Mailbox's IPv6 addresses are handled in step 3 below.

2

Create a mail flow rule to bypass spam filtering

The previous step tells Microsoft that Clean Mailbox is a trusted source, but on its own it doesn't always prevent SPF/DMARC-related rejections. The mail flow rule below explicitly forces Microsoft 365 to bypass spam filtering for any email relayed by Clean Mailbox.

1. Open the Exchange admin center

From All admin centers, this time click Exchange.

Microsoft 365 admin center - accessing Exchange
All admin centers → Exchange (shown here in French)

2. Open mail flow rules

In the left-hand menu, open Mail flow → Rules, then click Add a rule → Create a new rule.

Exchange admin center - Mail flow - Rules
Mail flow → Rules → Add a rule (shown here in French: "Flux de courrier" → "Règles")
Add a rule menu - Create a new rule
Select "Create a new rule" (shown here in French: "Créer une règle")

3. Set the condition

Give the rule a clear name (for example Bypass anti-spam - Clean Mailbox), then set the condition:

4. Set the actions

Under Do the following, add these actions:

Mail flow rule - conditions and actions
Sample rule: condition on the sender's IP, bypass actions (shown here in French)
SCL value - Bypass spam filtering
Value to select for the spam confidence level

Leave the other settings at their defaults, then save the rule. Double-check that it shows as Enabled in the rules list.

3

Disable IPv6 for the domain (recommended)

Microsoft 365 doesn't let you list IPv6 addresses the same way as IPv4 in the mail flow rule's graphical interface. To prevent an email relayed by Clean Mailbox over IPv6 from bypassing the rules configured above, we recommend disabling IPv6 for your accepted domain, so that our servers only ever talk to Microsoft 365 over IPv4.

Connect to Exchange Online PowerShell (Connect-ExchangeOnline), then run:

Disable-IPv6ForAcceptedDomain -Domain "yourdomain.com"

Replace yourdomain.com with your own domain name. This command is safe to run as long as all of your inbound mail already flows through Clean Mailbox.

Verify it works

Once the configuration is saved (it can take a few minutes to propagate), send a test email from an external domain with strict SPF/DMARC, and check:

Frequently asked questions

My emails are still being blocked after this configuration

Check that no other mail flow rule, with a higher priority (lower number), intercepts the message before the rule created in step 2. Also check, in the non-delivery report (NDR), that the IP address mentioned matches one of the Clean Mailbox IPs listed above.

Do I need a dedicated inbound connector?

For most Customers, the configuration above is sufficient. If you'd like Microsoft 365 to preserve the original sender IP's reputation (Microsoft's Enhanced Filtering for connectors feature), a dedicated inbound connector can be set up — contact us and we'll walk you through it.

Questions about the Clean Mailbox configuration?

Our support team can help you confirm the IP addresses to allow or diagnose a delivery issue. For the administration of your Microsoft 365 tenant itself, please reach out to Microsoft support or your IT provider.

Contact Clean Mailbox →

Let's protect your mailbox.

Questions about the trial, setup, pricing, or a partnership? We're here — and we answer fast.

30-day free trial, no card required
Works with any mail server
Setup in under 5 minutess
Infrastructure based in France 🇫🇷