WiseStamp for IT › Microsoft 365 › Step 5 of 12 — Server-Side Deployment
Plan requirement: Platform or Enterprise.
How it works
Outbound mail leaves Exchange Online, routes to the WiseStamp server-side host, gets the signature appended, and is delivered to recipients. Because the signature is applied in transit, it is consistent regardless of the sending device or client.
Server-side can run on its own or in hybrid mode with the Outlook Add-In. In hybrid, the server-side service only appends a signature when it does not already detect a WiseStamp signature on the message, preventing duplicates. See Setup Overview.
Prerequisites
Step 1 complete: Microsoft Entra ID directory connected (Connect Microsoft Entra ID).
Microsoft 365 Global Administrator rights.
Exchange admin access to Mail flow > Connectors and Rules.
DNS edit access for SPF (and ideally DKIM) records.
Network team briefed on routing hostnames; IP allowlist added if your firewall requires it (see below).
Option A — Automated configuration (recommended)
WiseStamp guides the connector setup from within the product.
Sign in to your WiseStamp account.
On the main navigation panel, click Integrations.
In the Server-side section, click Connect and select Microsoft Exchange.
Select I’m the Global Admin and click Connect.
Click Authorize, then select the relevant domains and click Connect.
Add SPF records to all domains that lack them, then click Verify.
Copy the code and click Connect. In the Microsoft pop-up, paste the code and click Next.
Close the tab. The Management page is displayed.
Then run the validity check (below) and configure signature rules (below).
Option B — Manual configuration
Use this when you need to build the Exchange Online mail flow yourself. Contact WiseStamp support to enable manual server-side configuration and to obtain your tenant’s routing code before you begin. Steps must be performed by a Microsoft Global Administrator.
The configuration has three phases: add connectors → create transport rules → validate.
Phase 1 — Add connectors
Outbound connector (routes your mail to WiseStamp):
In the Exchange admin center, go to Mail flow > Connectors and click Add a connector.
Connection from = Office 365; Connection to = Your organization’s email server. Click Next.
Name it: outbound ms.smtp.wisestamp.net. Click Next.
On Use of connector, select Only when I have a transport rule…. Click Next.
On Routing, enter your routing code followed by .ms.smtp.wisestamp.net (e.g. RFw0rAriJyW.ms.smtp.wisestamp.net). Click +, then Next.
On Security restrictions, select Add the subject name… and enter *.ms.smtp.wisestamp.net. Click Next.
On Validation email, enter your address, click +, then Validate. (Ignore validation-failure errors.) Click Next.
Review and click Create connector, then Done.
Inbound connector (authenticates mail returning from WiseStamp):
Go to Mail flow > Connectors and click Add a connector.
Connection from = Your organization’s email server. Click Next.
Name it: inbound outbound.smtp.wisestamp.net. Click Next.
On Authenticating sent email, select the first radio button and enter outbound.smtp.wisestamp.net. Click Next.
Review and click Create connector, then Done.
Phase 2 — Create transport rules
Rule 1 — Prevent out-of-office messages routing to WiseStamp:
Go to Mail flow > Rules > Add a rule > Create a new rule.
Name: Prevent Out of Office messages being sent to WS SMTP.
Apply this rule if: the message properties > include the message type > Automatic reply.
Do the following: modify the message properties > set message header X-Wisestamphostedsignatures-Messageprocessed to value true.
Click Next, Next, Finish. Set priority to 0.
Rule 2 — Identify messages to send to WiseStamp:
Go to Rules > Add a rule > Create a new rule.
Name: Identify messages to send to WS SMTP.
Apply this rule if: the sender is located inside the organization.
Do the following: redirect the message to the connector outbound ms.smtp.wisestamp.net, and set message header X-Wisestamphostedsignatures-Auth to your routing code.
Add four exceptions:
message size ≥ 26624 (bytes)
message header X-Wisestamphostedsignatures-Messageprocessed contains true
sender address matches <> (see note below)
sender is located outside the organization
Click Next, Next, Finish. Set priority to 1.
Enable the rules: On the Rules page, toggle each rule on. Then in WiseStamp go to Integrations > Server-side > Manually > Connect.
Phase 3 — Disable RTF (recommended)
Rich-text messages can break appended HTML signatures.
Exchange admin center > Mail flow > Remote domains.
Select Default, then Edit text and character set.
Under Use rich-text format, select Never. Click Save.
Network / firewall allowlist
Server-side routing references these hostnames:
ms.smtp.wisestamp.net (outbound, prefixed with your routing code)
outbound.smtp.wisestamp.net (inbound authentication)
IP ranges: see Prerequisites Checklist for the current Microsoft IPs behind these hostnames. Normally clients don’t need to add these IPs anywhere — hostname-based connectors/rules are sufficient — unless you run a spam-filtering service (e.g., Barracuda) in front of Exchange, in which case allowlist your domain or these IPs on that service.
Validation (validity check)
In WiseStamp, activate your user (status Active).
From Outlook, send a test email to yourself or a colleague and confirm the WiseStamp signature appears.
Test from a non-Outlook device (e.g., mobile mail app) to confirm cross-client coverage.
Ensure several admins have access to the Exchange admin center for rapid troubleshooting.
Full acceptance steps: Go-Live Checklist.
Server-side signature rules
After connecting, you can assign signatures by rule (Platform/Enterprise).
Path: Integrations > Server-side > Signature rules > Add rule.
Sender conditions: all employees / specific groups / specific employees.
Email type: all / new / reply.
Recipient conditions: all / at least one internal / all internal / at least one external / all external.
Priority: when multiple rules match, the higher-priority (higher number) rule wins.
Activate a rule with its Active toggle and confirm when prompted.
Emergency: disable routing
If outbound mail stops flowing, disable the routing rule so mail bypasses WiseStamp, then contact support:
Exchange admin center > Mail flow > Rules.
Open the rule Identify messages to send to WS SMTP.
Toggle it off.
Mail then delivers without a server-side signature. See Troubleshooting Reference. To re-enable later, see "Reconnect" in the same article.