Proofpoint Essentials setup
Proofpoint Essentials: inbound mail bypasses the gateway
The domain's public MX set or Microsoft 365 connectors may not match the selected Proofpoint deployment.
The visible symptom is:
Inbound mail bypasses Proofpoint Essentials or stops after the MX change.
Fix the mail route
- In Proofpoint Essentials, confirm the selected deployment: Direct MX or integrated Microsoft 365.
- Make sure the domain is imported, verified, and enabled for relay.
- For Direct MX, publish the MX records shown in Proofpoint Connection Details.
- Confirm the Proofpoint destination route reaches your mail system.
- For Microsoft 365, review the generated inbound connectors and the rule that blocks unintended direct delivery.
- Send a new external message and trace it in both Proofpoint and the destination service.
Common causes
The domain is imported but not enabled, MX records belong to another region, an old MX bypasses Proofpoint, or the Microsoft 365 locked-down connector was enabled before every legitimate route was allowed.
What the check proves
MailFixIt can show the public MX route. It cannot see connector state or determine whether Proofpoint accepted the recipient.
Frequently asked questions
Does every Proofpoint Essentials deployment change MX records?
No. Direct MX deployments do; newer integrated Microsoft 365 deployments can route through connectors without changing public MX records.
Does a correct DNS record prove the provider is using it?
No. The provider must also activate the matching route or signing policy. Confirm the result in its console and in a new message.
Related email diagnostics
Primary sources: Proofpoint Essentials: Microsoft 365 Direct MX integration.