{"id":494,"date":"2024-02-22T15:06:07","date_gmt":"2024-02-22T14:06:07","guid":{"rendered":"https:\/\/zupertails.be\/wur\/?p=494"},"modified":"2025-05-26T15:50:21","modified_gmt":"2025-05-26T13:50:21","slug":"sending-m365-mail-from-your-all-in-one-scanner-printer","status":"publish","type":"post","link":"https:\/\/zupertails.be\/wur\/?p=494","title":{"rendered":"Sending M365 mail from your all-in-one scanner\/printer"},"content":{"rendered":"<h2>DISCLAIMER : as of sep 2025 the method described below will no longer work according to https:\/\/learn.microsoft.com\/en-us\/exchange\/mail-flow-best-practices\/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365<\/h2>\n<p>&nbsp;<\/p>\n<h2>Precursor<\/h2>\n<p>Imagine the following : you recently migrated your mail platform from the &#8220;classic&#8221; POP\/IMAP mailbox setup towards Microsoft 356&#8217;s mail solution.<\/p>\n<p>If you&#8217;ve done the M365 setup correctly and migrated everything towards your new cloud environment (<a href=\"https:\/\/zupertails.be\/wur\/?p=108\">see tons of previous posts \ud83d\ude09<\/a>) you&#8217;ll soon run into some issues when trying to send an e-mail from your super-cool all-in-one printer\/scanner\/copy\/fax machine, which is hooked up to the network and ready to send scanned documents in your (domain) name.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-496\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/allinoneprinter.png\" alt=\"\" width=\"281\" height=\"273\" \/><\/p>\n<p>One of these issues being that you receive a NDR from your recipient relating to something like &#8220;<strong>Error 550 5.7.1 The user or domain that you are sending to (or from) has a policy that prohibited the mail that you sent<\/strong>&#8221; or anything basically that falls back to &#8220;<strong>we don&#8217;t trust this e-mail, because you smell of spam\/phishing\/malconfigured SMTP\/&#8230;<\/strong>&#8221;<\/p>\n<p>Your printer &#8211; in this example &#8211; still has port <strong>25<\/strong> and (for instance) <strong>uit.telenet.be<\/strong> as outgoing mail server <em>(yes, I&#8217;m Belgian &#8211; hence the .be TLD on my site)<\/em><\/p>\n<h6>(PS : don&#8217;t want to read this entire story ? CTRL-F your way to &#8220;How do I set this thing up ?&#8221;)<\/h6>\n<h2>Behind the scenes<\/h2>\n<p>What happened behind the scenes before and after your migration, concerning mail flow ?<\/p>\n<h4><strong>Before your migration<\/strong>,<\/h4>\n<p>you used to have and old-school mail provider that allowed a lot.<br \/>\nYour recipients didn&#8217;t care much or already added your scanned mails with PDF&#8217;s in them in their <del>white<\/del> allow-list.<br \/>\nMaybe your mails got through, maybe they didn&#8217;t.<\/p>\n<p>Your outgoing mail provider (let&#8217;s say it&#8217;s <em>Telenet nv<\/em> for the sake of the already mentioned example above) doesn&#8217;t really care what you send over their mail server, as long as you send it from an IP address on their network.<\/p>\n<h6>(a small note : at the time of this writing Telenet no longer accepts anonymous port 25; they need authentication through an @telenet.be address and use port 587 with TLS encryption)<br \/>\n(another small sidenote : Proximus still allows anonymous port 25 at this time *cough*)<\/h6>\n<p>Whatever the case, it would allow senders to send any mail they want from any e-mail address they want, as long as they use their own internet provider&#8217;s mail address.<\/p>\n<h4>After migrating to M365,<\/h4>\n<p>Microsoft kind of <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/admin\/get-help-with-domains\/create-dns-records-at-any-dns-hosting-provider?view=o365-worldwide\">enforces you to add certain DNS records<\/a>, before 100% completing the setup wizard of their Online Exchange offer.<br \/>\n\u2705 green ticks tick my own boxes as well, so as an OCD-enjoying IT guy, I <em>can&#8217;t not<\/em> complete this wizard :p<\/p>\n<p>One of these records you have to create is an SPF record, which partly regulates the mail flow for your domain by defining. (more on the SPF record on <a href=\"https:\/\/zupertails.be\/wur\/?p=187\">[this page]<\/a>)<br \/>\nMicrosoft is also kind enough to allow you to send over their own SMTP servers (good guy MS !!!) and provides certain regulations in order to be able to do so.<\/p>\n<p><strong>Server\/Smart Host<\/strong>: smtp.office365.com<br \/>\n<strong>Port<\/strong>: 587<br \/>\n<strong>TLS\/Start TLS<\/strong>: Enabled<br \/>\n<strong>Username\/Email address and password<\/strong>: pretty obvi what this is&#8230;.<\/p>\n<p>In a perfect world, you&#8217;d be able to just enter these settings in your super-duper all-in-one printer and you&#8217;d be good to go. \ud83d\udc4c<\/p>\n<p><strong>HOWEVER&#8230;<\/strong><\/p>\n<p>On the dreaded day of June 30, 2023 Microsoft disabled out-of-the-box support for a tiny little protocol we know as <em><strong>TLS<\/strong><\/em>.<br \/>\nSpecifically, they disabled support for TLS 1.0 and 1.1 (fear not).<br \/>\nA lot of these printers use this &#8220;older&#8221; protocol and &#8211; as you might already guess &#8211; this complicates the entire sending-of-mail process.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-499\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/never-fear-i-is-here-hackers.gif\" alt=\"\" width=\"220\" height=\"166\" \/><\/p>\n<p>Never fear, though !<\/p>\n<p>Microsoft built in a backdoor\/workaround in their own security enforcement and still allows you to send mails like you would in &#8220;days of olden&#8221;.<\/p>\n<p>&nbsp;<\/p>\n<h2>How do I set this thing up ?<\/h2>\n<p>We&#8217;ll take this random internet screenshot from the mail settings tab in an OKI printer as an example :<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-medium wp-image-500\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/OKIupload_2017-12-4_12-1-11-289x300.png\" alt=\"\" width=\"289\" height=\"300\" srcset=\"https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/OKIupload_2017-12-4_12-1-11-289x300.png 289w, https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/OKIupload_2017-12-4_12-1-11.png 581w\" sizes=\"(max-width: 289px) 100vw, 289px\" \/><\/p>\n<p>Following all instructions you find on the internet, this would be the way to go.<br \/>\nAnd it is.<\/p>\n<p>Using these settings in 2024 will result in a &#8220;cannot send mail&#8221; error on the printer.<\/p>\n<p>Did you misconfigure something on this printer ?<br \/>\nNO.<\/p>\n<p>Here&#8217;s what you need to change on the Microsoft side :<\/p>\n<ul>\n<li>Through <a href=\"https:\/\/admin.microsoft.com\">https:\/\/admin.microsoft.com<\/a> browse your <strong>Users &gt; Active Users<\/strong> and click the mail enabled user for your all-in-one device (Yes, you need to have a mail-enabled user for this)<\/li>\n<li>On the screen that appears on the right, go to the &#8220;Mail&#8221; tab and click &#8220;<strong>Manage email apps<\/strong>&#8220;<img loading=\"lazy\" class=\"aligncenter size-medium wp-image-501\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/M365mailapps-300x150.png\" alt=\"\" width=\"300\" height=\"150\" srcset=\"https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/M365mailapps-300x150.png 300w, https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/M365mailapps.png 620w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/li>\n<li>By default &#8220;<strong>Authenticated SMTP<\/strong>&#8221; is not active.<br \/>\nActivate it and press &#8220;<strong>save changes<\/strong>&#8221;<br \/>\n<img loading=\"lazy\" class=\"aligncenter size-medium wp-image-502\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/authenticated-smtp-300x250.png\" alt=\"\" width=\"300\" height=\"250\" srcset=\"https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/authenticated-smtp-300x250.png 300w, https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/authenticated-smtp.png 521w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/li>\n<li>That&#8217;s not where it stops, though.<br \/>\nMicrosoft, sneaky as they are, still disable <strong>SMTP AUTH<\/strong> on a more global level.<br \/>\nSo just activating the above, will result in the same sending error on your device.<br \/>\nsooooo, let&#8217;s go to <a href=\"https:\/\/admin.exchange.microsoft.com\">https:\/\/admin.exchange.microsoft.com<\/a> for part 2 of the config.<\/li>\n<li>On the Exchange Online admin center go to <strong>Settings<\/strong> (in the left) column and pick &#8220;<strong>Mail Flow<\/strong>&#8221; (not to be confused the the &#8220;Mail Flow&#8221; fold-out menu in the left column).<br \/>\n<img loading=\"lazy\" class=\"aligncenter size-medium wp-image-503\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/settings-mail-flow-300x220.png\" alt=\"\" width=\"300\" height=\"220\" srcset=\"https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/settings-mail-flow-300x220.png 300w, https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/settings-mail-flow.png 663w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/li>\n<li>One thing that needs to be de-activated is the &#8220;<strong>Turn off SMTP AUTH protocol for your organization<\/strong>&#8220;. (<em>the tick needs to be unticked &#8211; super confusing option &#8211; double negatives and all<\/em>)<br \/>\nDepending on the type of device, you may or may not need to opt-in the tick &#8220;<strong>Turn on use of legacy TLS clients<\/strong>&#8220;.<br \/>\nEven though Micro$oft disabled TLS 1.0 and 1.1, they still allow older TLS versions to communicate with the SMTP AUTH endpoint &#8220;smtp.office365.com&#8221;.<br \/>\n<img loading=\"lazy\" class=\"aligncenter size-medium wp-image-504\" src=\"http:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/mail-flow-settings-300x210.png\" alt=\"\" width=\"300\" height=\"210\" srcset=\"https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/mail-flow-settings-300x210.png 300w, https:\/\/zupertails.be\/wur\/wp-content\/uploads\/2024\/02\/mail-flow-settings.png 525w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/li>\n<li>Press &#8220;Save&#8221;, give it a couple of hours tops and BAM, send at will with your Brother MFC something something, your mail enabled camera system, CRM software, &#8230;<\/li>\n<\/ul>\n<p>I&#8217;ll leave the &#8220;<strong>plus addressing<\/strong>&#8221; tick for you to Google. It&#8217;s a cool feature, with little use-case.<br \/>\nStill cool though.<\/p>\n<p>I haven&#8217;t talked about using an account that uses MFA, where you could use &#8220;app passwords&#8221; up to 2024, but due to security reasons Microsoft is discontinuing this feature<\/p>\n<p>Peace out.<br \/>\nHappy mailing !<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DISCLAIMER : as of sep 2025 the method described below will no longer work according to https:\/\/learn.microsoft.com\/en-us\/exchange\/mail-flow-best-practices\/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365 &nbsp; Precursor Imagine the following : you recently migrated your mail platform from the &#8220;classic&#8221; POP\/IMAP mailbox setup towards Microsoft 356&#8217;s mail solution. If you&#8217;ve done the M365 setup correctly and migrated everything<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[8,6,9],"tags":[49,52,50,17,51],"_links":{"self":[{"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=\/wp\/v2\/posts\/494"}],"collection":[{"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=494"}],"version-history":[{"count":9,"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=\/wp\/v2\/posts\/494\/revisions"}],"predecessor-version":[{"id":561,"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=\/wp\/v2\/posts\/494\/revisions\/561"}],"wp:attachment":[{"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zupertails.be\/wur\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}