Skip to content

Microsoft 365

Fromenance is a communication provenance platform that answers forwards sent to verify@yourdomain.com. On Microsoft 365, that address is a mailbox or distribution group with an Exchange Online mail flow rule that redirects it to your tenant inbox.

By the end you will have verify@ created, a mail flow rule with Redirect the message to (not forward), ARC sealing and DKIM confirmed for your domain, and the forwarding test marked Working.

  • Exchange administrator role in the Microsoft 365 admin center.
  • Your tenant inbox address, verify_address in the setup wizard, for example northfield@verify.fromenance.com.
  • The domain verified in Fromenance.

As a shared mailbox (recommended, no license)

  1. Exchange admin center, Recipients, Mailboxes, Add a shared mailbox.
  2. Display name Verify, email verify@yourdomain.com. Do not add members.

As a distribution group

  1. Exchange admin center, Recipients, Groups, Add a group, type Distribution.
  2. Email verify@yourdomain.com. Under Settings, allow people outside the organization to send to the group. Do not add members.
  1. Exchange admin center, Mail flow, Rules, Add a rule, Create a new rule.

  2. Name: Fromenance verify redirect.

  3. Apply this rule if: The recipient > is this person, choose verify@yourdomain.com.

  4. Do the following: Redirect the message to > these recipients, and enter your tenant inbox northfield@verify.fromenance.com. Exchange accepts an external address here.

    Do not choose Forward the message for approval or Bcc the message. Both rewrite or copy; only redirect keeps the customer as the sender and the headers intact.

  5. Leave Except if empty.

  6. Rule settings: Enforce, severity Low, Stop processing more rules ticked so a later disclaimer or encryption rule cannot touch it. Match sender address in message: Header.

  7. Save and enable. Rules typically apply within 30 minutes.

3. Confirm authentication on the redirected copy

Section titled “3. Confirm authentication on the redirected copy”

Exchange Online adds an ARC seal to mail it processes. The seal is by your tenant’s domain when your accepted domain is configured for DKIM; Fromenance accepts an ARC chain whose last seal is by a domain you own, or a DKIM signature that verifies for one.

  1. Microsoft Defender portal, Email and collaboration, Policies and rules, Threat policies, Email authentication settings, DKIM.
  2. Select yourdomain.com and confirm Sign messages for this domain with DKIM signatures is enabled. If not, create the two selector1._domainkey and selector2._domainkey CNAME records shown and enable it.
  3. If the redirected copy is signed with yourtenant.onmicrosoft.com instead of your domain, the forwarding test reports domain_not_owned with that domain. Enable DKIM for your custom domain, or add the onmicrosoft.com domain to Fromenance with only the trust role and publish its TXT record.

Exchange Online seals with your domain only when it is the last hop before Fromenance. If a third party gateway (Proofpoint, Mimecast, Cisco) relays your outbound mail, that gateway must either preserve the Microsoft seal and the DKIM signature untouched or add its own ARC seal for your domain. Add your gateway to Trusted ARC sealers in Email authentication settings for inbound; for outbound, disable disclaimer stamping and body rewriting on the connector that carries the redirect.

  1. In the setup wizard, step 4, click Send test, or call POST /v1/domains/{id}/forwarding-test.
  2. Within a minute the status should read Working via arc yourdomain.com or Working via dkim yourdomain.com.
  3. failed: auth_failed with a body hash mismatch means something changed the message after signing, usually a disclaimer rule ordered after the redirect. Move the redirect rule above it and set Stop processing more rules.

Then forward any message from a personal mailbox to verify@yourdomain.com and confirm a Not verified reply arrives.

  • Do not set mailbox level forwarding on the shared mailbox (Mailbox, Email forwarding). That is a forward, and it also delivers a copy locally.
  • Outbound spam policies can block automatic external forwarding. If the redirect never leaves, open Microsoft Defender, Anti-spam policies, Anti-spam outbound policy, and set Automatic forwarding rules to On for the policy that covers verify@, or create a custom policy for that one address.
  • Attachment blocking rules can drop .eml forwards. Exempt verify@.