Simply put, the SMTP relay question remains unresolved. I am aware that we can directly route apps and devices to Exchange Online, but this involves a significant effort. Moreover, many devices lack internet access. The direct relay on port 587 necessitates open firewall ports, and ideally, a static IP address should be configured on the outbound NAT.
While this approach might work for fewer than 10 devices, many of our customers have a much larger number of devices. Consequently, they often choose to keep the last Exchange server operational. Unfortunately, the current options for correctly authenticating emails as ‘Internal’ within the Auth-Headers pose too many security risks.
Thanks for the feedback form: Done!