This guide is for a business email on your own domain hosted on Microsoft 365 (for example support@yourstore.com managed from Outlook). Microsoft blocks automatic forwarding to addresses outside the organization by default, and controls it with three separate settings: one of them blocking is enough for nothing to go out. Here are the three, in the order worth checking, and how to tell which one is yours.
If your email is @outlook.com, @hotmail.com or @live.com, this isn't your guide: those are personal accounts, with no admin and no policies. Your steps are in the forwarding guide, Outlook.com section.
mailipy sends you a test email when you click «Done — check it». What happens to that email tells you where the problem is.
| What happens to the test email | What it means | Where to look |
|---|---|---|
| It reaches your inbox and the connection stays «pending» | Outlook isn't forwarding it: forwarding isn't enabled in your mailbox, or Microsoft drops it silently | Step 1, then 2 |
| mailipy tells you it bounced with code 5.7.520 («Your organization does not allow external forwarding») | Your mailbox does forward it; the outbound anti-spam policy cuts it. The most common case | Step 2 |
| It bounces with another code or message | Usually a mail flow rule or the remote domain | Steps 3 and 4 |
| The connection gets verified | Done: don't touch anything else | — |
The first three are Microsoft settings; the fourth is checking again in mailipy.
Outlook in the browser → gear icon → Mail → Forwarding. Enable forwarding, paste your @mailipy.com address (the one mailipy shows you), tick «Keep a copy of forwarded messages» and save. Outlook doesn't ask you to confirm anything. Forwarding an email by hand with the «Forward» button doesn't count: forwarding is a setting.
Go to security.microsoft.com (you need to be an admin; in a small store that's usually you) → Email & collaboration → Policies & rules → Threat policies → Anti-spam. Open «Anti-spam outbound policy (Default)» → Edit protection settings → «Automatic forwarding» → choose «On - Forwarding is enabled» → Save.
Watch out: «Automatic - System-controlled» counts as blocked. And if the Anti-spam list has another outbound policy besides the default one, that one wins for the users it includes: open it and set it to «On» too. Microsoft applies to each user the highest-priority policy; the default one is always last.
Go to admin.exchange.microsoft.com → Mail flow → Remote domains → Default → «Edit reply types» → tick «Allow automatic forwarding» → Save. If there are also mail flow rules blocking external forwarding, remove them or add an exception for your @mailipy.com address.
On Home → «Connect your email» → «Finish», click «Done — check it». We send another test email: if your Outlook forwards it, the connection is verified in under a minute. If it bounces with 5.7.520 again, the policy from step 2 is still blocking (look for another outbound policy).
Because Microsoft stopped accepting username and password from other apps (app passwords included) on Outlook.com in September 2024 and on Microsoft 365 since 2023. It only accepts its own authorization system, which mailipy doesn't use. With a Microsoft email, forwarding is the only way, which is why the portal doesn't even offer the password route.
It's almost always a second outbound policy with higher priority than the default one. In the Anti-spam list, check whether there's more than one «outbound» policy; the highest-priority one is the one applied to your user. If there's only one, wait a few minutes and check again: Microsoft takes a moment to apply changes.
It's the code Microsoft returns to the sender when an email tried to auto-forward externally and the outbound anti-spam policy blocked it: «550 5.7.520 Access denied, Your organization does not allow external forwarding». The good thing about seeing it is that it confirms your mailbox is forwarding; only the policy is missing.
Ask whoever administers your Microsoft 365 for step 2 (and 3 if needed). It's a one-minute change and affects nothing but automatic forwarding. If that's not possible, the alternative is to use another mailbox for the store's support (a Gmail one, for example) and connect it by forwarding or with a password.
Write to us with a screenshot of the anti-spam policies list and of the bounce mailipy shows you, and we'll close it with you.
Email soporte@mailipy.com