Microsoft 365 Scan to Email Setup for Office Printers
A printer can copy perfectly while its email settings keep scanned invoices from reaching customers. Microsoft 365 scan to email works reliably when the sending method matches your printer, security policies, and recipient needs.
The first decision is whether scans stay inside your organization or must reach outside addresses. Start there, because the sending method determines the server, authentication, and network settings you'll need.
Choose your Microsoft 365 scan to email method
Microsoft 365 offers several ways for devices to send mail. However, they aren't interchangeable, and copying another office's printer settings can create delivery or security problems.
Use this comparison before changing the device.
| Method | Server and port | Authentication | Recipients |
|---|---|---|---|
| SMTP client submission | smtp.office365.com
, port 587 |
OAuth preferred; Basic authentication subject to restrictions | Internal and external |
| Microsoft 365 SMTP relay | Your tenant's MX endpoint, port 25 | Connector identifies a certificate or static public IP | Internal and external |
| Direct Send | Your tenant's MX endpoint, port 25 | No authentication | Internal only |
| High Volume Email (HVE) | smtp.hve.mx.microsoft
, port 587 |
HVE account authentication, with OAuth preferred | Internal only |
For a printer that supports Exchange Online OAuth, authenticated submission can be a practical choice. Meanwhile, SMTP relay can suit devices that cannot authenticate directly but operate behind a controlled business connection.
Direct Send requires fewer settings, but it can't deliver scans to customers or vendors outside your organization. HVE is another internal-mail option for applications and devices.
Before choosing, record each printer's model, firmware, sender address, and current authentication method. Also identify who manages your firewall, Microsoft 365 tenant, and domain DNS. Those systems often belong to different vendors, which can slow troubleshooting.
Configure authenticated SMTP submission
SMTP client submission sends through an Exchange Online mailbox. It requires a licensed mailbox, supported authentication, and access to Microsoft's submission endpoint.
Enter the correct server and encryption settings
Set the SMTP server to smtp.office365.com
and the port to 587
. Select STARTTLS, which upgrades the SMTP connection to an encrypted session.
The printer must support TLS 1.2 or TLS 1.3. Older devices limited to TLS 1.0 or TLS 1.1 cannot use this method.
Use the server's DNS name, not a fixed IP address. Microsoft's service addresses can change, so saving an IP can cause later failures.
Also verify the printer's DNS server, default gateway, clock, and firmware. Incorrect time or outdated certificate trust can prevent TLS negotiation.
Don't substitute port 465 with implicit SSL. Microsoft's documented client-submission configuration uses STARTTLS on port 587.
Configure the mailbox and sender identity
Use a dedicated device mailbox rather than an employee's account. Give it no administrative roles, and document which printers use it.
Where supported, configure OAuth for Exchange Online SMTP. A general "authentication enabled" checkbox doesn't prove the device supports OAuth.
For the simplest setup, match the printer's From address to the authenticated mailbox. If another mailbox supplies the sender address, configure the required Send As permission.
Tenant settings, mailbox permissions, and OAuth registration can require administrator work. SJC Technology's Microsoft 365 setup and support can help coordinate those settings with your printer configuration.
Set up SMTP relay or Direct Send correctly
These methods use your tenant's MX endpoint rather than smtp.office365.com
. Copy the exact MX value from your Microsoft 365 domain's DNS configuration.
Although both use port 25, their authorization and delivery capabilities differ.
Use a connector for SMTP relay
In the Exchange admin center, create an inbound connector for mail arriving from your organization's device or mail server. Configure it to identify your source using a supported TLS certificate or a static public IP address.
For IP-based identification, use the office's public internet address, not the printer's private LAN address. A changing ISP address can break the connector match.
Configure the printer to send to the tenant MX endpoint on port 25. Use a sender address in a Microsoft 365 accepted domain, and configure STARTTLS with TLS 1.2 or later.
Relay doesn't require a licensed sending mailbox. However, it needs carefully restricted connector and firewall settings so unauthorized devices can't use your business connection to send mail.
Keep Direct Send internal
Direct Send uses the tenant MX endpoint on port 25 without mailbox authentication or a relay connector. It delivers only to recipients in your Microsoft 365 organization.
Use STARTTLS when the printer supports it. Also account for the sending public IP in your SPF configuration, following Microsoft's guidance.
A successful internal test doesn't prove external delivery works. If staff need to scan directly to customer addresses, choose another method.
Check SMTP AUTH availability and the 2026 timeline
SMTP AUTH is the protocol used for authenticated SMTP submission. Basic authentication is one way to authenticate through it, using a username and password.
Microsoft's retirement plans concern Basic authentication , not the entire SMTP AUTH protocol.
Use the current retirement schedule
As of September 2026, Microsoft's revised schedule leaves SMTP AUTH Basic authentication behavior unchanged until December 2026. Existing tenant restrictions still apply.
In December 2026, Microsoft plans to disable it by default for existing tenants. New tenants created after December 2026 will have it unavailable by default.
Microsoft says it will announce the final removal date in the second half of 2027. The earlier March and April 2026 rejection dates were superseded.
A saved password might still work today, but it's a poor foundation for a new deployment. Choose OAuth or a suitable relay architecture before password-based sending becomes a business interruption.
Review tenant and mailbox controls
Administrators must check both organization-wide SMTP AUTH settings and the designated mailbox's setting. Authentication policies can also block Basic authentication even when SMTP AUTH appears enabled.
Microsoft recommends keeping SMTP AUTH disabled broadly and allowing it only where needed.
Security Defaults blocks legacy Basic authentication and affects SMTP AUTH availability. Don't disable Security Defaults merely to make an old copier work.
Instead, review device capabilities and supported sending alternatives. Include printers in your Microsoft 365 MFA rollout planning, because authentication changes can interrupt unattended devices.
App passwords remain Basic authentication. They don't convert an older printer into an OAuth-capable device.
Consider High Volume Email for internal workflows
Microsoft 365 High Volume Email is another option for internal messages generated by devices and applications. It uses dedicated HVE accounts rather than ordinary mailbox submission.
The recommended server is smtp.hve.mx.microsoft
. Microsoft's older smtp-hve.office365.com
endpoint is scheduled for future deprecation, so avoid it for a new setup.
HVE supports up to 100 accounts per tenant . Its published limits include 50 recipients per message and a 10 MB message size.
That size limit matters for scanned documents. Large color PDFs can exceed it, so test actual scanning profiles rather than a small text-only page.
HVE requires OAuth when Security Defaults is enabled. Confirm that the printer or an intermediary application supports the required authentication.
Because HVE delivers internally, it won't solve a requirement to email scans directly to outside customers. Also check current availability, limits, and commercial terms before adopting it for a production workflow.
Protect the printer, sender, and scanned documents
A working Microsoft 365 scan to email configuration still needs security controls. Printers store address books, settings, and sometimes document data, so they deserve regular maintenance.
Restrict device and account access
Change default printer administrator credentials and install supported firmware updates. Place printers on a dedicated network segment with firewall rules that allow only required traffic.
Keep printer management interfaces off the public internet. For relay, limit which devices can send through the trusted public IP.
Use the least permissions needed for device accounts and administrative access. Remove unused SMTP AUTH permissions, old accounts, and abandoned connectors.
Assign an owner to each device and credential. Then include certificate renewal, OAuth reauthorization, and configuration backups in routine maintenance.
Align email protection with scan delivery
Inventory every service that sends mail for your domain, including copiers. Maintain one SPF record and stay within SPF's 10-DNS-lookup limit.
Configure DKIM and DMARC for your sending domain, and verify results through your chosen sending path. Don't assume one DNS change covers every method.
Also retain anti-phishing and attachment protections, including Defender for Office 365 controls where licensed. Investigate quarantined scans rather than broadly bypassing filtering.
TLS protects the connection to the mail service. It doesn't make an emailed scan end-to-end encrypted or prevent a recipient from forwarding it.
For sensitive records, use an approved protected-document workflow and restrict recipient choices at the device.
Test delivery and troubleshoot common printer failures
Test the complete workflow before staff depend on it. Use a non-sensitive document, then verify the attachment arrives and opens correctly.
For methods that support external recipients, test one internal mailbox and one approved external address. Record the time, sender, recipient, and any device error.
Separate connection failures from authentication failures
A connection timeout usually points to DNS, routing, firewall rules, or ISP restrictions. Port 25 blocking commonly affects relay and Direct Send; port 587 access matters for authenticated submission.
A TLS error suggests unsupported encryption, incorrect device time, outdated firmware, or certificate-validation problems.
Authentication failures require a different review. Check credentials or OAuth authorization, mailbox licensing, SMTP AUTH availability, and tenant policies.
Capture the full SMTP response before changing settings. Repeated password resets can obscure the cause while disrupting other devices using the same account.
For connector relay, also verify that the office's public IP still matches the connector.
Trace accepted messages that don't arrive
Use Message trace in the Exchange admin center to check messages accepted by Exchange Online. Then review quarantine, mail-flow rules, recipient restrictions, and message-size limits.
A sender-permission failure can occur when the From address differs from the authenticated mailbox. Meanwhile, oversized scans may fail after smaller tests succeed.
If multiple printers stop together, check Microsoft 365 admin center Health > Service health before changing every device.
Document the final settings and retest after ISP, firewall, firmware, or authentication-policy changes. Ongoing IT support for email and printers helps keep these dependencies visible.
Keep scan delivery reliable without weakening security
Reliable scanning starts with the right sending method . Match recipient needs and printer capabilities before configuring authentication, encryption, and network access.
Keep the final settings documented, assign an owner, and test after infrastructure or policy changes. That makes a failed scan easier to diagnose without weakening Microsoft 365 protections or interrupting the rest of your office.

