Changing DNS MX records to route all inbound mail through Defender for Office 365
You have a Microsoft 365 subscription that contains 1,000 Microsoft Exchange Online mailboxes. Incoming email from the internet is scanned for security threats by using a third-party cloud service. You are evaluating whether to replace the third-party service with Microsoft Defender for Office 365. What should you modify to ensure that all the incoming email is scanned by Defender for Office 365 only?
Community Votes
56% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Mail routing is controlled by MX records; pointing MX to Microsoft EOP/Defender reroutes all inbound mail through Defender. Connectors (D) manage flow after delivery and cannot by themselves guarantee that a third party no longer receives and scans the mail first.
To ensure all internet inbound email is scanned exclusively by Microsoft Defender for Office 365 (replacing a third-party filtering service), update the DNS MX records to point to Microsoft's Exchange Online Protection, so mail flows through Defender rather than the third party.
Modifying Exchange Online connectors (D) — connectors manage mail flow after delivery but do not guarantee that a third-party gateway no longer receives and scans the mail first; the MX record controls where mail is delivered.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Inbound mail routing on the internet is governed by the domain's MX (Mail Exchanger) DNS records. To make Microsoft Defender for Office 365 the sole scanner of inbound mail, you repoint the MX records to Microsoft's Exchange Online Protection endpoints so all inbound messages are delivered to and filtered by Defender, removing the third-party service from the path.Why the Other Options Are Wrong
Exchange Online connectors (D) control how mail is accepted/relayed after it arrives but do not move the delivery destination; as long as MX still points at the third party, that service scans first. Accepted domains (A) and transport rules (C) do not change where inbound mail is delivered.Community Comment Notes
The community was split (B 56 / D 44). The correct control for 'scanned by Defender ONLY' is the MX record, because only changing MX removes the third party from the mail path; connectors alone cannot guarantee exclusivity. Several comments confirm updating MX to Microsoft is required.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →