Forward email from Microsoft 365
Summary
Section titled “Summary”You keep your own address, such as support@yourcompany.com, and let Microsoft
365 deliver a copy of every message to KonversAI. The rule that does this is a
mail flow rule in the Exchange admin center. KonversAI receives the mail at the
ingress address shown on the Email tab of the Entry-points screen in the
KonversAI console. Microsoft 365 blocks forwarding to outside addresses by
default, so a mailbox forwarding set-up needs one extra change that a mail flow
rule does not.
Who can do this
Section titled “Who can do this”Two roles, in two different products. An Exchange administrator in Microsoft 365 creates the mail flow rule in the Exchange admin center, and a Global Administrator changes the outbound spam filter policy when you use mailbox forwarding. A Tenant Admin in KonversAI copies the ingress address and runs the forwarding test on the Email tab of the Entry-points screen. KonversAI answers Only tenant admins can modify email engagement configs. to anyone else.
Before you start
Section titled “Before you start”Set up the email channel in KonversAI first. You need an email configuration with an ingress address. The forwarding test sends a message from the current send-from address (the ingress address by default) and waits for your rule to return it. See Set up the email channel.
Add your own address under Receiving e-mail on the Email tab of the Entry-points screen in the KonversAI console. Only an address that is added and verified there accepts mail into your tenant.
Get administrator access to the Exchange admin center. You cannot create a mail flow rule without it.
- Select Settings in the left sidebar of the KonversAI console, then select Entry-points. Select the Email tab.
- Open Receiving e-mail. Copy the ingress address with the copy button next to it. You paste this address into Microsoft 365 in step 6.
- Open the Exchange admin center at
admin.exchange.microsoft.com. - Select Mail flow → Rules, then Add a rule → Create a new rule.
- Name the rule, such as
Support to KonversAI. Under Apply this rule if, select The recipient and is this person, then select the address customers write to, such assupport@yourcompany.com. - Under Do the following, select Add recipients and to the Bcc box, then type the ingress address you copied in step 2. This keeps the message in the mailbox and sends a copy to KonversAI. Select Redirect the message to instead when you do not want a copy to stay in the mailbox.
- Select Next, review the rule, and select Finish. Set the rule to Enabled. A new mail flow rule can take up to 30 minutes to apply.
- Return to the Email tab of the Entry-points screen in the KonversAI console. Select Test next to your own address under Receiving e-mail. KonversAI sends a test message to that address and waits for your rule to return it. The status changes to Verified when the message arrives.
Why must the forwarding rule keep the sender address?
Section titled “Why must the forwarding rule keep the sender address?”KonversAI reads the sender address of each inbound message to work out which customer wrote it. A rule that keeps the sender address gives every customer their own conversation history in KonversAI, and lets a reply go back to the person who wrote. A rule that replaces the sender address makes every message look like it came from one sender, so KonversAI cannot tell your customers apart and replies go to the wrong place. A mail flow rule in Microsoft 365 keeps the sender address.
Microsoft 365 returns “550 5.7.520 Access denied”. What do I do?
Section titled “Microsoft 365 returns “550 5.7.520 Access denied”. What do I do?”Microsoft 365 blocks automatic forwarding to addresses outside your
organisation by default, and the ingress address that KonversAI generates is
outside your organisation. The sender gets an error that reads 550 5.7.520
Access denied, Your organization does not allow external forwarding. Open the
Microsoft Defender portal at security.microsoft.com and select Email &
collaboration → Policies & rules → Threat policies → Anti-spam. Open your
outbound spam filter policy, and set Automatic forwarding rules to On -
Forwarding is enabled. Check your remote domain settings in the Exchange admin
center as well: when either setting blocks forwarding, the message does not go
through. Then select Test again next to your address under Receiving
e-mail on the Email tab of the Entry-points screen in the KonversAI
console.
Can I forward the mailbox instead of using a mail flow rule?
Section titled “Can I forward the mailbox instead of using a mail flow rule?”Yes, with one extra step. Open the Microsoft 365 admin center at
admin.microsoft.com, select Users → Active users, select the mailbox, open
the Mail tab, and select Manage email forwarding. Type the ingress
address shown under Receiving e-mail on the Email tab of the
Entry-points screen in the KonversAI console, and keep a copy in the mailbox
if you want one. Microsoft 365 blocks forwarding to outside addresses by
default, so you also need to set Automatic forwarding rules to On -
Forwarding is enabled in your outbound spam filter policy, in the Microsoft
Defender portal under Email & collaboration → Policies & rules → Threat
policies → Anti-spam. A mail flow rule avoids that change.
Does a distribution list work?
Section titled “Does a distribution list work?”A distribution list in Microsoft 365 keeps the sender address of the original message, so mail that arrives through one can reach KonversAI correctly. A mail flow rule is still the better choice, because it applies to one address and leaves your list membership alone. Whichever you use, run the forwarding test: select Test next to your address under Receiving e-mail on the Email tab of the Entry-points screen in the KonversAI console. KonversAI checks the sender address on the test message and tells you when the route replaces it.
The forwarding test does not complete. What is wrong?
Section titled “The forwarding test does not complete. What is wrong?”KonversAI shows Forwarding test did not complete in time. Check forwarding rules and try again. when the test message does not come back within two minutes. The usual cause in Microsoft 365 is the external forwarding block: see the FAQ entry about 550 5.7.520 Access denied on this page. Check as well that your rule sends to the exact ingress address shown under Receiving e-mail on the Email tab of the Entry-points screen in the KonversAI console, and that the rule is Enabled. A new mail flow rule can take up to 30 minutes to apply. A test expires after 30 minutes, and the status becomes Expired, with the message The forwarding test never arrived back at KonversAI. Check that forwarding from this address is switched on and does not filter mail from us, then run the test again. Select Test again after you correct the rule.
KonversAI shows Your forwarding rule changes the sender address. KonversAI cannot tell your customers apart. Use a routing rule instead of a group or mailing list. when the test message comes back under a different address. Move the route to a mail flow rule, then select Test again.
Last reviewed . Tell us when a step no longer matches the product.