When selecting O365 as an outbound email source what security ESS use to confirm?
Email Security.cloud
When Office 365 is configured as an outbound source, Email Security.cloud validates the SMTP session based on the configured outbound routes. This ensures that only authorized servers (such as your O365 tenant) are permitted to relay outbound mail through the service.
Emails originating from other (non-approved) Office 365 tenants are treated as inbound traffic unless explicitly configured otherwise. This ensures proper security inspection and prevents unauthorized relay or spoofing attempts.
Additionally, Anti-EchoSpoofing protection helps prevent spoofed messages from being incorrectly identified as internal or trusted, adding another layer of verification.
For detailed configuration steps and in-depth information, please refer to the following documentation: