Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

Sophos Central Email, 5.7.1 Service unavailable; Unverified Client host...

Trying to configure email using custom gateway for the first time (I've configured a bunch for gmail/ms365 before, no problems).

So this customer needs to be able to send from onprem via sophos, I've verified the domain and added the mailboxes (aad directory sync).

Added their wan ip (added to spf) as outbound custom gateway.

Tried sending test email via telnet, when that didn't work I tried hmailserver.

Sophos says:

554 5.7.1 Service unavailable; Unverified Client host [reverse dns of host] blocked using uri.ire2.sophosxl.com

What may I be missing here?