Skip to main content

Exchange Server Email Signature Setup: Prerequisites Checklist

Check admin rights, plan tier, mailbox topology, DNS and firewall rules before connecting WiseStamp to Exchange. Requirements differ per topology and method.

WiseStamp for IT › Exchange › Step 2 of 12 — Prerequisites Checklist


Audience: IT manager / system administrator. Complete this before Identity & Employee Sync.


1. Administrative access

Requirement

Applies to

Notes

Microsoft 365 Global Administrator

Off-prem / hybrid (EXO)

Required for Entra ID integration, Add-In central deployment, and server-side connector authorization. Sign into Microsoft in a separate tab before starting.

Exchange admin access to Mail flow > Connectors and Rules

Server-side (off-prem/hybrid)

Required to create/verify connectors and transport rules in the Exchange admin center.

WiseStamp Owner or Admin role

All

Access the Integrations page. See Permissions Reference.

On-prem Exchange admin (Organization Management) + Exchange Management Shell

Pure on-prem

Not applicable — pure on-prem is not supported. Employee sync is not supported for on-prem; no plan supports it.


2. WiseStamp plan

Method

Minimum plan

Outlook Add-In + Entra ID employee sync

Basic

Server-side routing + signature rules

Platform

SSO (SAML)

Platform

Security Group sync

Enterprise (or trial)


3. Topology & mailbox requirements

Requirement

Applies to

Notes

Exchange Online with active mailboxes

Add-In

The Add-In requires Exchange Online mailboxes.

Directory in or federated to Entra ID

Off-prem / hybrid

Required for directory sync and Add-In identity.

Outbound mail egress via Exchange Online

Hybrid

Server-side routing is documented at the EXO egress point.

On-prem mail flow control (Send/Receive connectors, transport)

Pure on-prem

Not supported. Employee sync is not supported for on-prem; no plan supports it.

Supported Outlook clients (Add-In)

  • Microsoft 365 Business (Standard/Premium) v1701+

  • Office 365 Enterprise (E1/E3/E5/F3) v1701+

  • Microsoft 365 Enterprise (E3/E5/F3) v1701+

  • Office for Mac 16.0.9318.1000+

  • Outlook mobile iOS 2.75.0+ / Android 2.2.145+

  • Outlook on the web

Note: build minimums are from the help center and undated. WiseStamp could not confirm a specific verification date but believes these floors are still correct.


4. Email authentication (DNS) — server-side

Requirement

Notes

SPF

Add include:outbound.smtp.wisestamp.net to your sending domains' SPF before routing through WiseStamp.

DKIM

Routing through WiseStamp can break existing DKIM. WiseStamp issues a unique DKIM record per account — request it from support, add as TXT, then have support enable signing. Verify dkim=pass.


5. Network / firewall allowlist — server-side

Server-side routing references these WiseStamp hostnames:

  • Outbound target: ms.smtp.wisestamp.net (prefixed with your tenant routing code, e.g. <routing-code>.ms.smtp.wisestamp.net)

  • Inbound authenticating domain: outbound.smtp.wisestamp.net

IP ranges (Exchange Online and hybrid):

104.198.34.229
34.133.172.126
35.224.156.40
34.173.9.51
35.225.126.165
34.173.64.165

Normally clients don’t need to add these IPs anywhere — hostname-based connectors/rules are sufficient — unless you run a spam-filtering service (e.g., Barracuda) in front of Exchange, in which case allowlist your domain or these IPs on that service. Pure on-prem is not supported, so this list does not apply.


6. Pre-flight checklist

  • ☐ Topology identified (off-prem / hybrid / on-prem).

  • ☐ WiseStamp plan supports the intended method.

  • ☐ Microsoft 365 Global Admin confirmed (off-prem/hybrid).

  • ☐ Exchange admin access to Mail flow (server-side).

  • ☐ WiseStamp Owner/Admin access confirmed.

  • ☐ (Add-In) EXO mailboxes; Outlook builds meet minimums.

  • ☐ (Server-side) SPF updated; DKIM record requested/added; signing enabled.

  • ☐ (Server-side) Allowlist hostnames in place; IP list added if required (see IP ranges above).

  • ☐ (Pure on-prem) Confirmed not supported — employee sync is not supported for on-prem and no plan supports it; migrate identity to Entra ID (hybrid, at minimum) before proceeding.

Related articles


Did this answer your question?