How to Configure Journaling to Two Separate Mimecast Journals in Microsoft 365
Question details
The user needs to configure email journaling for two separate Mimecast entities in a hybrid Microsoft 365 setup without messages being rejected as an open relay.

- Product
- Microsoft Exchange Hybrid
- Device & OS
- not provided
- Scenario
- Routing journal messages properly across two distinct on-premises domains and two separate Mimecast environments.
- Observed behavior
- Journal messages are being routed through the default domain and subsequently rejected by the second Mimecast entity as an open relay.
Ensure you have global administrator or Exchange administrator credentials for your Microsoft 365 tenant, as well as administrative access to both Mimecast Administration Consoles to review authorized outbound addresses and internal directories.
Review Mail Flow Connectors and Consult Exchange Specialists
Because hybrid routing with multiple third-party archiving endpoints requires intricate mail-flow logic, verifying your accepted domains and consulting specialized hybrid management communities is the recommended path.
In a dual-domain hybrid environment, traffic meant for a specific Mimecast journal can easily default to the primary tenant routing, causing the destination Mimecast server to interpret the message as unauthorized (open relay). Resolving this involves strictly isolating routing rules.
Log in to the Microsoft 365 Exchange admin center. Navigate to Mail flow > Accepted domains, and ensure both on-premises domains are properly configured and recognized by Exchange Online.
Go to Mail flow > Connectors. Inspect the outbound connectors routing mail to Mimecast. Verify that sender domain restrictions or transport rules strictly govern which connector is used for each domain's journal traffic.
In both Mimecast Administration Consoles, verify that the sending IP addresses and routing domains are registered in the Internal Directories and Authorized Outbound lists to prevent open relay rejections.
Since this configuration requires highly specialized mail-flow guidance, post your exact connector and accepted-domain setup in the Microsoft Exchange Hybrid Management section of Microsoft Learn to get expert validation from experienced administrators.

Streamline Your Organization's Document Workflow with WPS Office
While resolving complex Exchange Hybrid mail-flow and Mimecast journaling issues requires deep technical troubleshooting, managing your organization's daily documents doesn't have to be complicated. WPS Office is a powerful, cost-effective alternative to Microsoft Office that empowers your team to create, edit, and share documents effortlessly.

Frequently Asked Questions
Why does Mimecast reject the journaled messages as an open relay?
Mimecast rejects messages as an open relay when the incoming email originates from an IP address or domain that is not registered within the Mimecast Internal Directories or Authorized Outbound lists. When mail routes through the wrong default domain connector in Microsoft 365, Mimecast fails to recognize it as internal traffic.
Can I set up multiple journaling rules in Microsoft 365?
Yes, Microsoft 365 supports multiple journal rules. You can configure different rules in the Microsoft Purview compliance portal to send journal reports to distinct SMTP addresses based on specific recipients, senders, or group memberships.
How do I validate my outbound connectors in Exchange Online?
Navigate to the Exchange admin center, click on 'Mail flow', and select 'Connectors'. Select the specific connector used for Mimecast, click 'Validate this connector', and enter an external email address to test if the routing and authorization are functioning correctly.




