SOLVED

Confused - need clarification

%3CLINGO-SUB%20id%3D%22lingo-sub-911554%22%20slang%3D%22en-US%22%3EConfused%20-%20need%20clarification%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-911554%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20read%20this%20article%20regarding%26nbsp%3B%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fhow-to-set-up-a-multifunction-dev...%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESend%20mail%20from%20Multiple%20devices%2Fapplication%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOption%201%20is%20the%20MS%20'%3CSTRONG%3E%3CEM%3ERecommended%3C%2FEM%3E%3C%2FSTRONG%3E'%20one%20-%20but%20then%26nbsp%3Bthere's%20this%20kind%20of%20%22disclaimer%22%20in%20the%20bottom%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E%3CEM%3E%22%3C%2FEM%3E%3C%2FSTRONG%3E%3CSPAN%3E%3CSTRONG%3E%3CEM%3EIf%20you%20happen%20to%20have%20an%20on-premises%20email%20server%2C%20you%20should%20seriously%20consider%20using%20that%20server%20for%20SMTP%20relay%20instead%20of%20Office%20365%22%3C%2FEM%3E%3C%2FSTRONG%3E%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWhy%20should%20one%20%22seriously%20consider%22%20this%3F%20-%20what's%20'wrong'%20with%20option%201%3F%26nbsp%3B%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EIn%20this%20related%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fhow-to-configure-iis-for-relay-with-office-365%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fhow-to-configure-iis-for-relay-with-office-365%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EAre%20the%20IIS%20option%20considered%20as%20the%20'best%20solution'%20in%20'relaying'%20towards%20O365%3F%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ELooking%20for%20the%20'Best'%20solution%20possible%20-%20security-wise%26nbsp%3B%3C%2FSPAN%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-911554%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-911581%22%20slang%3D%22en-US%22%3ERe%3A%20Confused%20-%20need%20clarification%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-911581%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F108979%22%20target%3D%22_blank%22%3E%40Taen%20keren%3C%2FA%3E%2C%3CBR%20%2F%3E%3CBR%20%2F%3EWith%20SMTP%20services%20it%20is%20traditionally%20recommended%20to%20repurpose%20an%20old%20on%20premise%20Exchange%20(if%20in%20hybrid)%20or%20use%20a%20cloud%20server%20like%20Hyper%20V%2FAzure%20as%20it%20takes%20the%20load%20off%20of%20365%20and%20you%20have%20greater%20management%20(having%20access%20to%20IIS%20etc).%20These%20would%20then%20sit%20behind%20a%20smart%20host%20such%20as%20Mimecast%20to%20protect%20the%20domain%20(s)%20against%20blacklisting.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20security%20terms%20both%20are%20secure%20whether%20you%20go%20through%20365%20or%20spin%20up%20a%20VM%20with%20IIS.%20Just%20make%20sure%20if%20it%E2%80%99s%20the%20second%20option%20to%20lock%20down%20open%20relaying!%20Oh%2C%20forgot%20to%20add%20that%20the%20second%20option%20of%20the%20VM%20does%20have%20the%20benefit%20of%20permitting%20non-auth%20SMTP%20too%20whereas%20365%20does%20not%20-%20this%20is%20good%20for%20legacy%20devices%20and%20apps!%3CBR%20%2F%3E%3CBR%20%2F%3EHad%20much%20fun%20with%20this%20in%20the%20past%20as%20you%20can%20tell!%20%3BD%20%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20that%20answers%20your%20question!%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-911589%22%20slang%3D%22en-US%22%3ERe%3A%20Confused%20-%20need%20clarification%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-911589%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F169605%22%20target%3D%22_blank%22%3E%40Christopher%20Hoard%3C%2FA%3E%26nbsp%3B%20-%20Thx%20-%20option%201%20is%20the%20best%20then%20-%20as%20the%20'legacy%20part'%20is%20not%20good%26nbsp%3B%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Super Contributor

I've read this article regarding  Send mail from Multiple devices/application 

 

Option 1 is the MS 'Recommended' one - but then there's this kind of "disclaimer" in the bottom: 

 

"If you happen to have an on-premises email server, you should seriously consider using that server for SMTP relay instead of Office 365"

 

Why should one "seriously consider" this? - what's 'wrong' with option 1?  

 

In this related article https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-configure-iis-for-relay-wi... 

Are the IIS option considered as the 'best solution' in 'relaying' towards O365? 

 

Looking for the 'Best' solution possible - security-wise  

 

2 Replies
best response confirmed by Taen keren (Super Contributor)
Solution
Hi @Taen keren,

With SMTP services it is traditionally recommended to repurpose an old on premise Exchange (if in hybrid) or use a cloud server like Hyper V/Azure as it takes the load off of 365 and you have greater management (having access to IIS etc). These would then sit behind a smart host such as Mimecast to protect the domain (s) against blacklisting.

In security terms both are secure whether you go through 365 or spin up a VM with IIS. Just make sure if it’s the second option to lock down open relaying! Oh, forgot to add that the second option of the VM does have the benefit of permitting non-auth SMTP too whereas 365 does not - this is good for legacy devices and apps!

Had much fun with this in the past as you can tell! ;D

Hope that answers your question!

Best, Chris

@Christopher Hoard  - Thx - option 1 is the best then - as the 'legacy part' is not good  :)