CONBOOL
  • Blog
  • Dokumentation
  • Partner
  • Kontakt
Loslegen
CONBOOL

Sichere und automatisierte E-Mail-Sicherheit für Unternehmen – einfach, zentral und zuverlässig.

© Copyright 2026 Conbool. Alle Rechte vorbehalten.

Auszeichnungen
  • OMR Leader Badge für E-Mail-Sicherheit
Mitglied bei
  • Bitkom Mitglied – Digitalverband
  • BSI Allianz für Cyber-Sicherheit – Mitglied
Über uns
  • Blog
  • FAQ
  • Partner
  • Kontakt
Produkt
  • SecureMail
  • MailGuard
  • Disclaimer
  • Dokumentation
Add-ins
  • Disclaimer
  • SecureMail
  • SecureFiles
Rechtliches
  • Nutzungsbedingungen
  • Datenschutzerklärung
  • Impressum
Dokumentation
  • Rollen & Berechtigungen

Open-Xchange

Mail server variant for Open-Xchange, OX App Suite and OX Mail. Smart host and mailfilter Sieve rules.

Prerequisite: Step 1, Domain & DNS Setup is complete and all four DNS checks are green.

What happens here: The OX MTA, the Postfix stack under Open-Xchange, is configured to use Conbool as its smart host. Inbound connections from Conbool are allowed. Loop protection and spam classification run via mailfilter Sieve rules. In the Setup Assistant, the Manual configuration mode is chosen.

Effort: 30 to 60 minutes.


Step A. Outbound Smart Host in OX

Navigation: OX server administration → Mail server configuration, or directly in the Postfix configuration.

FieldValue
Smart host or relay hostmail.conbool.com
Port25
AuthenticationNone, identification via TLS certificate and sender domain
TLSRequired
TLS certificate namemail.conbool.com
MX lookup for smart hostDisabled
ScopeAll hosted domains, optionally specific domains of the OX installation

Step B. Allow Inbound Connections from Conbool

So that Conbool may deliver mail to OX, the Conbool IP addresses are added as a trusted relay source.

  1. Receiving MTA: Make port 25 for SMTP reachable from the Conbool IP addresses. Conbool provides the IP list.
  2. Recipient whitelist: Accept only the domains hosted in OX, i.e. standard recipient restrictions.
  3. TLS: Require for inbound connections from Conbool.
  4. Certificate validation: Allow TLS certificate name mail.conbool.com.

Firewall: Port 25 (SMTP) must be open from the Conbool IP addresses to the OX MTA. If running behind a load balancer, maintain the whitelist there as well.


Step C. Loop Protection and Spam in mailfilter Sieve Rules

OX has no central transport rule engine like Exchange. The logic is implemented via mailfilter Sieve rules per tenant or global, or via Postfix header checks.

  • Loop protection. Messages with X-Conbool-<YourDomain>: true (e.g. X-Conbool-example-com: true) must not be sent through Conbool again. Deliver directly via the regular MX.
  • Spam classification. Messages with X-Conbool-Flag: YES go to the Spam folder. Sieve action fileinto "Spam" or marker X-Spam-Flag: YES.
  • Calendaring and empty Return-Path. Calendaring messages and Return-Path: <> are excluded from smart-host routing.

If an OX-internal connector module or a third-party mail-routing plugin is used, apply the conditions above as exceptions in its rule set.


Done When

Back in the Setup Assistant at the Mail Server step. Enter the relay host of the OX inbound MTA, for example mx-internal.yourcompany.com, then click Test Connection. Status "SMTP reachable" means the connection is established.

Continue with the connection test and completion.

Auf dieser Seite

  1. Step A. Outbound Smart Host in OX
    1. Step B. Allow Inbound Connections from Conbool
    2. Step C. Loop Protection and Spam in mailfilter Sieve Rules
    3. Done When