Exchange mail flow guides › Outbound: send connectors and smart hosts
Hosting several companies or domains on one Exchange Server: separate inbound mailboxes and outbound relays
One Exchange Server can serve several domains. Inbound, each domain is an accepted domain with its own provider mailboxes or its own MX record; outbound, each domain must leave through the relay that is allowed to send for it — and that is where Exchange falls short, because it selects a send connector by the recipient’s domain and never by the sender. The inbound side is configuration that Exchange has built in; the outbound side needs a relay that routes by sender, such as MultiSendcon.
Updated on 2026-10-05
The Exchange behaviour on this page is taken from Microsoft Learn, where it is documented for Exchange Server 2016, 2019 and Subscription Edition; the connector and relay side is taken from the POPcon and MultiSendcon pages, help and knowledge base.
What “several domains” means to Exchange
Exchange does not know companies. It knows one organization, a list of accepted domains, and recipients with email addresses. Microsoft’s Accepted domains in Exchange Server puts it in one sentence: “Accepted domains are a global setting for the Exchange organization, and you can have multiple accepted domains of the same or different types.” And for the usual case: “An organization can be configured with multiple authoritative domains.”
So two companies on one server are, technically, two accepted domains and two groups of mailboxes whose addresses end differently. Which type each domain gets depends on where its recipients are:
| Accepted domain type | When Microsoft says to use it | Non-delivery reports for unknown recipients | Usable in email address policies |
|---|---|---|---|
| Authoritative | “when all recipients in that domain exist in your Exchange organization” | Exchange is responsible for generating them | Yes |
| Internal relay | Some of the recipients do not exist in the organization, for example “you share the domain between the Exchange organization and a third-party messaging system” | Exchange is not responsible; a send connector with the domain’s address space relays the rest | Yes |
| External relay | “None of the recipients in the external relay domain exist in the Exchange organization” | Exchange is not responsible | No |
A company whose mailboxes all live on your server gets an authoritative domain. Microsoft’s procedures page gives the two ways to add one: in the Exchange admin center under Mail flow › Accepted domains, or in the Exchange Management Shell:
New-AcceptedDomain -Name "Company B" -DomainName company-b.com— the type defaults to Authoritative.Get-AcceptedDomain | Format-Table -Auto Name,DomainName,DomainType,Default,AddressBookEnabled— Microsoft’s own check of what is configured.
A domain that is missing from this list is the classic cause of 550 5.7.1 Unable to relay when a connector submits mail for it; that case is described in 550 5.7.1 Unable to relay when a connector submits to Exchange.
One address per user in the right domain: email address policies
Accepting a domain does not yet give anybody an address in it. That is the work of email address policies, which Microsoft describes as “the rules that create email addresses for recipients in your Exchange organization” (Email address policies in Exchange Server). Three of their properties matter with several companies:
- The recipient filter “specifies the recipients whose email addresses are configured by the policy”. The precanned filters can select by recipient type, Company, Department, State or Province and the custom attributes 1 to 15. “Property values require an exact match”: a Company value of Company B does not match Company B Ltd.
- The primary address. One template in a policy defines the primary SMTP address, and Microsoft calls it “the Reply-To: email address for recipients”. This is the address the user sends from, and therefore the address the outbound relay will see.
- The priority. “If a recipient is identified by multiple email address policies, the recipient’s email addresses are only configured by the first email address policy that’s evaluated”, a lower number is evaluated first, and “the default email address policy is always evaluated last”. The policy for the second company therefore needs a higher priority than the default policy, or its users keep the first company’s address.
A practical arrangement is one policy per company, filtered by the Company attribute of the user accounts, each with its own domain in the primary address template.
Inbound: getting each domain’s mail to the server
There are two ways for a domain’s mail to reach Exchange, and they can be mixed per domain. Either the domain’s MX record points at your server and mail arrives by SMTP, or the mail stays in mailboxes at the provider and a connector collects it. The choice between the two is the subject of POP3 retrieval or MX record to Exchange; nothing about it changes with a second domain, except that it is made once per domain.
For the collected domains, POPcon is a Windows service that downloads mail from POP3 and IMAP mailboxes and submits it to Exchange over SMTP. Its account settings define the type per account:
- Single User: “All emails from this account are delivered to a single Exchange mailbox.” One provider mailbox per person, in whichever domain it belongs to. Nothing needs to be told apart: the account says where the mail goes.
- Catch-All: “Emails are distributed to multiple Exchange mailboxes based on recipient address analysis.” One provider mailbox per domain collects everything for that domain. With two companies this means two catch-all accounts, one at each provider.
Catch-all accounts need one more setting. A single download can contain mail for many recipients, and POPcon “must decide which recipients are local (to be delivered to Exchange) and which are not”. The field Accepted Recipient Domains on the POP3/IMAP configuration tab lists the domains POPcon should handle; the knowledge base article Why does POPcon need to know the accepted domains? describes what happens without it: delivery attempts to unknown addresses, Exchange errors, or everything re-routed to the postmaster. When a second company is added, its domain goes into this field as well as into Exchange. What catch-all mailboxes can and cannot do in general is covered in Catch-all mailbox or one POP3 mailbox per user.
When the server holds only part of a domain
A branch office, or a company that keeps some mailboxes at the provider, has only part of a domain on the Exchange server. An authoritative domain is then the wrong type by Microsoft’s definition, because not all recipients exist in the organization: Exchange would answer mail to the colleagues at the provider with a non-delivery report instead of sending it out. Microsoft’s answer is the internal relay domain together with a send connector for that domain’s address space.
The POPcon knowledge base describes a second arrangement for the collecting side in Configuring POPcon for a branch office that handles only part of a domain: Exchange accepts an internal domain such as branchoffice.local; the branch users get two SMTP addresses, the company address as the default reply address and one in the internal domain; and in POPcon’s catch-all settings “Auto replacement of recipient domains” rewrites the incoming company domain to the internal one. Users keep sending from the company address, and Exchange no longer considers the company domain its own.
Outbound: why one smart host is not enough
Inbound, the domains never get in each other’s way. Outbound they do, because all mail of the server leaves by the same rules. Exchange chooses a send connector by the recipient’s domain, the connector’s address space, and by cost and scope; Microsoft’s connector selection rules contain no criterion for the sender. A second send connector with the second company’s smart host therefore does not send the second company’s mail; the details and the attempts that fail are in Exchange send connectors route by recipient domain, not sender.
This matters as soon as the provider checks who is sending. A provider relay is an authenticated account, and providers tie the permitted sender addresses to that account. IONOS documents the rule: since January 2024 its outgoing servers accept a message only when the sender address is in the domain of the mailbox used for the login. Company B’s mail sent through company A’s login is refused with Sender address is not allowed (Using IONOS, Strato or GMX as the smart host for Exchange).
MultiSendcon is a Windows service that receives all outbound mail from Exchange through one send connector and forwards each message through the SMTP relay account that matches its sender. What can be set per account is listed on its help page for SMTP account settings:
| Per relay account | What it is for with several companies |
|---|---|
| SMTP server, port, user name and password | Each company’s own provider relay and login; ports are “typically 25, 587, or 465” |
| Sender Address Filter | *@company-a.com for all senders of a domain, or user@company-a.com for one address; left blank, the account matches all senders |
| Recipient Address Filter | Restricts an account to certain recipients, in the same format |
| Local IP Address | On a system with several network cards, which card handles this account — a separate outgoing address per company where that is required |
| HELO/EHLO Domain | The name the relay session announces itself with, per account |
| Fixed Sender Address Replacement | Replaces the sender with a fixed address where a provider requires the address of the authenticated account |
The order of the accounts decides when more than one matches: “the topmost entry in the list takes priority” (Relay Servers configuration). An account with an empty sender filter at the bottom of the list therefore catches every sender that no company account claimed. On the Exchange side nothing is company-specific: one send connector for all domains points at the address and port MultiSendcon listens on, by default port 2500, and the installer can create it. The step-by-step setup is in Multiple smart hosts in Exchange 2016/2019.
Non-delivery reports and automatic replies are a special case, because Exchange sends them with an empty sender that belongs to no company. What a provider does with them, and how the relay fills in a sender, is described in NDRs for external senders behind a POP3 connector.
A worked example: two companies, two providers
Company A has its domain and mailboxes at IONOS, company B at a second provider. Both work on the same Exchange Server.
| Setting | Company A | Company B |
|---|---|---|
| Accepted domain in Exchange | company-a.com, authoritative | company-b.com, authoritative |
| Email address policy | Recipient filter Company = Company A, primary address in company-a.com | Recipient filter Company = Company B, primary address in company-b.com |
| Inbound collection (POPcon) | Accounts at provider A, Single User or Catch-All | Accounts at provider B, Single User or Catch-All |
| Accepted Recipient Domains (POPcon, for Catch-All) | Both domains listed | |
| Send connector in Exchange | One connector for all domains, pointing at MultiSendcon | |
| Relay account (MultiSendcon) | Provider A’s SMTP server, login of a mailbox in company-a.com, sender filter *@company-a.com | Provider B’s SMTP server, login of a mailbox in company-b.com, sender filter *@company-b.com |
A workable order: add the second accepted domain and the address policy first and check that the users of company B show the right primary address; then add the collecting accounts and the domain in POPcon and send a test message to each domain from outside; then install MultiSendcon, add one relay account per company, use the built-in account test, and send one message from a user of each company to an external address. The headers of the two received messages show which provider relayed each of them.
What stays shared
Two companies on one Exchange organization are not two tenants. Three things remain common, and it is better to know them before promising separation to either company:
- The accepted domains and the default domain. Accepted domains are organization-wide, and “one accepted domain is always configured as the default domain”. Microsoft lists what it is used for, among other things “the external postmaster address:
postmaster@<default domain>”. There is only one. - The address book. Without further configuration every user sees every other user in the global address list. Microsoft’s address book policies let administrators “segment users into specific groups to provide customized views of the organization’s global address list”, with two notes from the same page: they “create only a virtual separation of users from a directory perspective, not a legal separation”, and implementing them “is a multi-step process that requires planning”.
- The transport path. Mail between the two companies never leaves the server; it is internal mail. The organization-wide message size limits and the send connector are the same for both.
When it does not work: where to look
| What you see | Cause | Where it is described |
|---|---|---|
| Collected mail for the new domain is refused with 550 5.7.1 Unable to relay | The domain is not an accepted domain in Exchange | Unable to relay guide |
| Catch-all mail for the new domain ends up with the postmaster | The domain is missing under Accepted Recipient Domains in POPcon | Knowledge base |
| Users of company B send with a company A address | The email address policy for company B does not match them or is evaluated after another policy | Section on email address policies above |
| Company B’s outbound mail is rejected by the provider with Sender address is not allowed | All mail leaves through company A’s provider login | Provider smart host guide |
| Mail to a colleague whose mailbox is still at the provider comes back as undeliverable | The domain is authoritative although not all its recipients are on the server | Section on partial domains above; knowledge base |
Frequently asked questions
Can one Exchange Server receive mail for several domains?
Yes. Microsoft describes accepted domains as a global setting for the Exchange organization and states that you can have multiple accepted domains of the same or different types, and that an organization can be configured with multiple authoritative domains. Each domain whose mailboxes live on the server is added as an authoritative accepted domain; email address policies then give each group of users its address in the right domain.
Does each company need its own send connector?
A second send connector does not solve it. Exchange selects a send connector by the recipient's domain, its address space, and never by the sender, so two connectors with two smart hosts do not split the mail by company. With a relay that routes by sender, Exchange needs one send connector that hands all outbound mail to the relay; the relay then picks the provider and the login per sender domain.
Do I need one POP3 or IMAP account per domain?
You need at least one provider mailbox per domain that is collected, because each provider mailbox belongs to one domain. In POPcon every account is either a Single User account, delivered to one Exchange mailbox, or a Catch-All account, distributed by recipient address. For Catch-All accounts each domain must be listed under Accepted Recipient Domains, otherwise POPcon cannot tell which recipients are local.
Can the users of company A see company B in the address book?
By default yes: the companies share one Exchange organization and one global address list. Microsoft provides address book policies to give groups of users their own view of the address list, and notes that they create only a virtual separation of users from a directory perspective, not a legal separation. Implementing them is, in Microsoft's words, a multi-step process that requires planning.
Which domain does Exchange use for its own postmaster address?
The default domain. Microsoft states that one accepted domain is always configured as the default domain and that it is used in the external postmaster address, postmaster@<default domain>. There is one default domain per organization, not one per company, so decide which company's domain it should be, typically an authoritative one.
More in the Exchange mail flow guides, on the MultiSendcon and POPcon product pages, the MultiSendcon download page and the POPcon download page, or in the knowledge base. Auf Deutsch: Mehrere Firmen oder Domains auf einem Exchange Server.