Microsoft 365
Fromenance is a communication provenance platform that answers forwards sent to verify@yourdomain.com. On Microsoft 365, that address is a mailbox or distribution group with an Exchange Online mail flow rule that redirects it to your tenant inbox.
By the end you will have verify@ created, a mail flow rule with Redirect the message to (not forward), ARC sealing and DKIM confirmed for your domain, and the forwarding test marked Working.
Before you start
Section titled “Before you start”- Exchange administrator role in the Microsoft 365 admin center.
- Your tenant inbox address,
verify_addressin the setup wizard, for examplenorthfield@verify.fromenance.com. - The domain verified in Fromenance.
1. Create the verify@ address
Section titled “1. Create the verify@ address”As a shared mailbox (recommended, no license)
- Exchange admin center, Recipients, Mailboxes, Add a shared mailbox.
- Display name
Verify, emailverify@yourdomain.com. Do not add members.
As a distribution group
- Exchange admin center, Recipients, Groups, Add a group, type Distribution.
- Email
verify@yourdomain.com. Under Settings, allow people outside the organization to send to the group. Do not add members.
2. Create the mail flow rule
Section titled “2. Create the mail flow rule”-
Exchange admin center, Mail flow, Rules, Add a rule, Create a new rule.
-
Name:
Fromenance verify redirect. -
Apply this rule if: The recipient > is this person, choose
verify@yourdomain.com. -
Do the following: Redirect the message to > these recipients, and enter your tenant inbox
northfield@verify.fromenance.com. Exchange accepts an external address here.Do not choose Forward the message for approval or Bcc the message. Both rewrite or copy; only redirect keeps the customer as the sender and the headers intact.
-
Leave Except if empty.
-
Rule settings: Enforce, severity Low, Stop processing more rules ticked so a later disclaimer or encryption rule cannot touch it. Match sender address in message: Header.
-
Save and enable. Rules typically apply within 30 minutes.
3. Confirm authentication on the redirected copy
Section titled “3. Confirm authentication on the redirected copy”Exchange Online adds an ARC seal to mail it processes. The seal is by your tenant’s domain when your accepted domain is configured for DKIM; Fromenance accepts an ARC chain whose last seal is by a domain you own, or a DKIM signature that verifies for one.
- Microsoft Defender portal, Email and collaboration, Policies and rules, Threat policies, Email authentication settings, DKIM.
- Select
yourdomain.comand confirm Sign messages for this domain with DKIM signatures is enabled. If not, create the twoselector1._domainkeyandselector2._domainkeyCNAME records shown and enable it. - If the redirected copy is signed with
yourtenant.onmicrosoft.cominstead of your domain, the forwarding test reportsdomain_not_ownedwith that domain. Enable DKIM for your custom domain, or add theonmicrosoft.comdomain to Fromenance with only thetrustrole and publish its TXT record.
ARC sealing note
Section titled “ARC sealing note”Exchange Online seals with your domain only when it is the last hop before Fromenance. If a third party gateway (Proofpoint, Mimecast, Cisco) relays your outbound mail, that gateway must either preserve the Microsoft seal and the DKIM signature untouched or add its own ARC seal for your domain. Add your gateway to Trusted ARC sealers in Email authentication settings for inbound; for outbound, disable disclaimer stamping and body rewriting on the connector that carries the redirect.
4. Confirm with the forwarding test
Section titled “4. Confirm with the forwarding test”- In the setup wizard, step 4, click Send test, or call
POST /v1/domains/{id}/forwarding-test. - Within a minute the status should read Working via arc yourdomain.com or Working via dkim yourdomain.com.
failed: auth_failedwith a body hash mismatch means something changed the message after signing, usually a disclaimer rule ordered after the redirect. Move the redirect rule above it and set Stop processing more rules.
Then forward any message from a personal mailbox to verify@yourdomain.com and confirm a Not verified reply arrives.
- Do not set mailbox level forwarding on the shared mailbox (Mailbox, Email forwarding). That is a forward, and it also delivers a copy locally.
- Outbound spam policies can block automatic external forwarding. If the redirect never leaves, open Microsoft Defender, Anti-spam policies, Anti-spam outbound policy, and set Automatic forwarding rules to On for the policy that covers
verify@, or create a custom policy for that one address. - Attachment blocking rules can drop
.emlforwards. Exemptverify@.