I am running a hybrid environment with Office 365. All mailboxes are in Exchange Online and I am trying to minimize my Exchange 2013 footprint on-prem. My programs, printers, and devices point to a DNS record that goes to our Netscalers. The Netscaler sends email to the hybrid server (Exchange 2013 CU12), then up to 365, via certificate.

When I test an email from one of my devices, it is successful if the email address is internal (same domain). But if the email is external I get the error message that the email address is invalid, and the email is not sent.

I have set the receive connector for the hybrid to 'Anonymous Users' only. I have included the IP addresses of the netscaler.

If I set the recieve connector to include the authentication option of TLS, then the external email will go through. The only problem is that the path is as followes: Device > Netscaler > hybrid server > other on-prem Exchange server > hybrid server > 365.

I am trying to get rid of the 'other on-prem Exchange server'. Any suggestions would be appreciated. Been working on this for a couple of weeks, and ready to get it off my plate.

Hi Jason,


I think the problem could be that you are pointing to the connector directly.


You can create a receive connector on Office 365 that receives from your Public IP and then you can point your Netscaler to your MX Record that will connect to your connector.


See option 2 on this article -



Thanks for the fast response.  Let me see if I get this right:  Since my hybrid has a NAT to an external IP (example:, and that IP is in my SPF record, and the receive connector in 365 has the cert which has the SAN that points to that IP:  all I would need to do is point the Netscaler to our MX record, and it will go through the hybrid?



1. Would I need to change the connector in 365 to accept by IP or does the cert work?

2. Can I NAT the netscaler out, and add the IP and be able to remove the hybrid from the equation?  



Hi Jason,


You can chose the 2 options, it always depends what you need. For me I always prefer to keep hybrid because the management, but you can have your scanners pointed directly to your MX with the connector created like the article says.


You can keep the connetor for the hybrid and create a new one.

Thanks Nuno for your help.  This might get me closer to our overall end goal of no exchange environment.  But the following article got me going by changing up the receive connector a little bit.  Now both internal and external emails are sending out through the hybrid to 365 EOP.


