AWS SMTP & M365 Security

Job ID: 40559217

Budget: ₹12,500 – ₹37,500 INR

We are looking for an experienced freelancer to design and deploy a secure, scalable, multi-tenant SMTP Gateway on AWS that integrates with Microsoft 365 Exchange Online using Exchange Online Connectors.
The SMTP Gateway will become part of our Enterprise Data Loss Prevention (DLP) solution and will process outbound emails for multiple enterprise customers.
Project Overview
Enterprise customers will configure Microsoft 365 Exchange Online Outbound Connectors to route their outgoing emails through our SMTP Gateway hosted on AWS.
The SMTP Gateway will:
• Accept secure SMTP connections from Microsoft 365 Exchange Online.
• Identify the customer (tenant) based on connector configuration, sender domain, certificate, or other recommended mechanism.
• Receive the complete email over TLS.
• Submit the email to our DLP application for security inspection.
• Obtain a synchronous allow/block decision from the DLP engine during the SMTP transaction (before issuing the final SMTP response).
• If approved, relay the email securely to its intended destination.
• If blocked, reject the SMTP transaction with the appropriate SMTP response so that Microsoft 365 generates a standard Non-Delivery Report (NDR) to the sender.
• Maintain SMTP queues, logs, monitoring, and retry mechanisms.
• Support multiple enterprise customers through a secure multi-tenant architecture.
The solution should be modular and designed so that Google Workspace integration can be added in the future.
Scope of Work
• Deploy a dedicated AWS EC2 instance.
• Install and configure a production-grade SMTP Gateway (Postfix preferred, but open to recommendations).
• Configure secure SMTP relay.
• Configure Microsoft 365 Exchange Online Connectors.
• Configure TLS certificates and secure SMTP communication.
• Configure DNS records (SPF, DKIM, DMARC, PTR, etc.) where required.
• Recommend and implement the appropriate DKIM strategy (preserve existing signatures where possible or perform per-tenant DKIM signing if required) while maintaining SPF, DKIM, and DMARC compliance.
• Configure message queues and retry mechanisms.
• Configure logging, monitoring, health checks, and troubleshooting tools.
• Secure the SMTP Gateway against unauthorized access, abuse, and open relay vulnerabilities.
• Integrate the SMTP Gateway with our DLP application through an API, local service, milter/content filter, or another recommended approach.
• Provide complete deployment documentation and architecture diagrams.
• Assist with end-to-end testing using Microsoft 365.
Architecture Expectations
The proposed solution should include:
• Secure multi-tenant architecture.
• Tenant identification and configuration management.
• Synchronous DLP inspection during the SMTP session.
• High availability and future horizontal scalability.
• Secure storage of tenant configuration and secrets.
• Comprehensive logging, monitoring, and auditing.
• Modular architecture for future Google Workspace support.
Required Skills
• AWS EC2
• Linux Administration (Ubuntu or Amazon Linux)
• Postfix (preferred) or equivalent SMTP Gateway
• SMTP, ESMTP, TLS and email routing
• Microsoft 365 Exchange Online Connectors
• Email security best practices
• DNS (SPF, DKIM, DMARC, PTR)
• Queue management and monitoring
• Experience building secure email gateways or similar email infrastructure
Good to Have
• Experience integrating SMTP gateways with DLP or Secure Email Gateway (SEG) products.
• Experience with Google Workspace SMTP routing.
• Experience designing scalable or highly available SMTP infrastructure on AWS.
• Experience with multi-tenant SaaS architectures.
Deliverables
• Production-ready SMTP Gateway deployed on AWS.
• Secure integration with Microsoft 365 Exchange Online.
• Integration interface with our DLP engine.
• Multi-tenant architecture capable of supporting multiple enterprise customers.
• Deployment documentation.
• Architecture diagram.
• Successful end-to-end testing.
• Knowledge transfer session.
While Applying, Please Include
• Brief introduction.
• Relevant SMTP Gateway / Email Security projects completed.
• Experience with Microsoft 365 Exchange Online Connectors.
• Your proposed solution architecture.
• Which SMTP Gateway software you recommend (Postfix, Exim, Haraka, etc.) and why.
• How you would implement the synchronous DLP inspection workflow.
• How you would design the multi-tenant architecture, including tenant identification, configuration storage, per-tenant policies, and scalability.
• Whether you recommend a database and what it would be used for.
• Your recommended DKIM strategy for a multi-tenant deployment.
• Your recommended Exchange Online connector configuration (TLS partner connector, certificate-based authentication, IP-based authentication, etc.) and the rationale.
• How you would approach IP reputation management and tenant isolation as the platform scales.
• Estimated timeline.
• Expected budget.
• Availability for post-deployment support.
Confidentiality
This project involves enterprise email security infrastructure and may process sensitive customer email data. Shortlisted candidates will be required to sign a Non-Disclosure Agreement (NDA) .