Proofpoint Essentials setup

Proofpoint Essentials: inbound mail bypasses the gateway

The domain's public MX set or Microsoft 365 connectors may not match the selected Proofpoint deployment.

Problem description

The visible symptom is:

Inbound mail bypasses Proofpoint Essentials or stops after the MX change.

Check the sending domain

Fix the mail route

  1. In Proofpoint Essentials, confirm the selected deployment: Direct MX or integrated Microsoft 365.
  2. Make sure the domain is imported, verified, and enabled for relay.
  3. For Direct MX, publish the MX records shown in Proofpoint Connection Details.
  4. Confirm the Proofpoint destination route reaches your mail system.
  5. For Microsoft 365, review the generated inbound connectors and the rule that blocks unintended direct delivery.
  6. Send a new external message and trace it in both Proofpoint and the destination service.

Common causes

The domain is imported but not enabled, MX records belong to another region, an old MX bypasses Proofpoint, or the Microsoft 365 locked-down connector was enabled before every legitimate route was allowed.

What the check proves

MailFixIt can show the public MX route. It cannot see connector state or determine whether Proofpoint accepted the recipient.

Frequently asked questions

Does every Proofpoint Essentials deployment change MX records?

No. Direct MX deployments do; newer integrated Microsoft 365 deployments can route through connectors without changing public MX records.

Does a correct DNS record prove the provider is using it?

No. The provider must also activate the matching route or signing policy. Confirm the result in its console and in a new message.

Related email diagnostics

Primary sources: Proofpoint Essentials: Microsoft 365 Direct MX integration.