office 365 Hybrid email Routing

As engaged with office 365 migration therefore I am learning more & more about office 365 and one of the interesting topic is email routing to & from exchange online /on-premise.

There are two options that are suggested by Hybrid wizard

  • Typical
  • Centralized


When you select Typical , internal mail flow i.e

Exchange online to Exchange on-premise & vice versa happens thru Hybrid servers but internet email from  Exchange online routes using EOP & from Exchange on-premise routes whatever you have already defined in connectors (example: third party gateways). This is also known as Decentralized routing.

When you select “Enable Centralized mail transport” , internal mail flow i.e

Exchange online to Exchange on-premise & vice versa happens thru Hybrid servers along with internet email , That’s why it is called Centralized routing & is generally selected by enterprise customers as they want to control the flow for different security purposes.

When you run the hybrid wizard what it  does is create connectors in on-prem/ cloud environment based on the option you choose.

You can edit these connectors based on your requirements for mail routing.( be cautious as it will impact routing)


For example:

In one configuration where we were using third-party cloud as email gateway , we have Chosen Typical mail flow & after that added a connector on EOP to route all the internet email via third party gateway ( you need to do settings on third party device so that it can accept email for relay from office 365). This configuration had removed the extra overhead of routing the email internally & than reaching third party.

You have to select Partner organization when configuring the out bound connector from EOP to Internet.

There are other solutions that happen while you work thru the setup for enterprises, As per Microsoft Recommendation they need direct connection(NAT ) from exchange online to hybrid hub servers , no devices should interfere in between the mailflow as that can alter the headers. Only supported device if your organization doesn’t want to direct NAT SMTP is having edge servers in the DMZ.

Here is what we have done for one organization & Microsoft told us that they will not assist in this configuration but if it will work than its fine.

We have reverse proxy the 443 as well as port 25 behind F5 & made it work , This can cause performance issues with large enterprises during mailbox moves as well as SMTP traffic performance can get affected that’s why MS or other cloud members always ask for direct connection but some time situation doesn’t favor because of security concerns raised by the organization so you need to think outside the box & mitigate the concerns.


Sukhija Vikas


2 thoughts on “office 365 Hybrid email Routing

  1. Hi Vikas,

    How did you reverse proxy the 443 and port 25 behind F5? What sort of performance issues did you face with this setup? We have several devices between EOL and EXO. Our mail-flow is like this:-

    Incoming mail flow is like this – Internet > Cisco > Trend IMVSA > Exchange 2016
    Outgoing mail is like this – Exchange 2016 > DLP > Edge Transport > Trend IMVSA > Cisco > Internet

    We have to setup centralized transport because client wants to keep the legacy devices.

    This is hybrid migration,

    Please advise. Thanks

  2. Too many hops will definitely cause some seconds to minute of delay to mail flow in our case we had one security appliance in between as well which we removed to get the performance as it was redundant.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s