CONBOOL
  • Blog
  • Dokumentation
  • Partner
  • Kontakt
Loslegen
CONBOOL

Sichere und automatisierte E-Mail-Sicherheit für Unternehmen – einfach, zentral und zuverlässig.

© Copyright 2026 Conbool. Alle Rechte vorbehalten.

Auszeichnungen
  • OMR Leader Badge für E-Mail-Sicherheit
Mitglied bei
  • Bitkom Mitglied – Digitalverband
  • BSI Allianz für Cyber-Sicherheit – Mitglied
Über uns
  • Blog
  • FAQ
  • Partner
  • Kontakt
Produkt
  • SecureMail
  • MailGuard
  • Disclaimer
  • Dokumentation
Add-ins
  • Disclaimer
  • SecureMail
  • SecureFiles
Rechtliches
  • Nutzungsbedingungen
  • Datenschutzerklärung
  • Impressum
Dokumentation
    • Eingehende Regeln
    • Ausgehende Regeln
    • Routing Priorität
        • Managed PKI
        • Auto Import
        • Auto Zertifikatsausstellung
        • Zertifikatsexport
        • Zertifikatsimport
        • Zertifikate ausstellen
        • Eigene Zertifizierungsstellen
        • SwissSign S/MIME
        • Schlüsselerstellung
        • Schlüsselexport
        • Schlüsselimport
        • Konfiguration
        • Zustellprozess
        • Antworten und Interaktionen
        • Portalkonfiguration
      • PDF-Verschlüsselung
  • Rollen & Berechtigungen

Message Portal

The Conbool Message Portal enables secure email communication without certificates or keys — with magic links, threading, quotas and audit log.

Message Portal — Overview

The Conbool Message Portal is the third option for secure email communication alongside S/MIME and PGP. Unlike certificate-based methods, it requires no certificates or keys. Recipients access their messages via a short-lived, cryptographically secured magic link.

Particularly convenient: senders continue to send directly from Outlook or any other email client. The message is automatically redirected to the portal in the background through routing and stored there in encrypted form.

How Does the Portal Work?

  1. Sender sends an email as usual via Outlook or another client.
  2. Conbool detects based on the routing rules that portal delivery should occur.
  3. The message is encrypted and stored in the portal (AES-encrypted EML).
  4. The recipient receives a notification via email with a magic link.
  5. The recipient clicks the link and views the message in the browser — including attachments.
  6. The recipient can reply directly in the portal — the reply is delivered back encrypted.

Security Features

Magic Links

  • Single-use: Each link can only be used once for authentication.
  • Time-limited: Links have a configurable expiration date.
  • Session-bound: The link is bound to the browser session and IP address.
  • Cryptographically signed: Manipulation of the link is detected.

Integrity Check

Each stored message has a SHA-256 content hash. Integrity is verified on every retrieval:

  • integrityOk: true — Message has not been altered.
  • integrityOk: false — Possible manipulation detected (logged in the audit log).

Delivery Modes

ModeDescription
portal_secureExternal recipients: Notification only via email, content only accessible through the portal.
relayInternal recipients: Full content is delivered via relay, additionally stored in the portal.

Threading & Replies

The portal supports full conversations:

  • External recipients reply directly in the portal (no account required).
  • Internal recipients (Conbool customers) can also reply via email client — Conbool automatically assigns the reply to the thread via the In-Reply-To header.
  • Thread depth: Maximum 30 messages per thread.
  • Notification: The sender is notified via email about new replies.

Storage & Quotas

Tenant Quota

The total storage quota of a tenant is calculated from the subscription:

  • Per SecureMail unit: 2 GB storage.
  • Additional portal quota depending on the plan.

Member Quotas

Storage can be limited per member:

SettingDescription
Default QuotaApplies to all members without an individual quota (default: 2 GB)
Individual QuotaConfigurable per member under Portal > Storage

When a member has reached their quota, no new messages can be sent via the portal until storage is freed up.

Retention & Deletion

SettingDescription
Retention PeriodMessages are automatically deleted after X days (configurable, default: unlimited)
Per-Message ExpirySenders can set an individual expiration date per message
Bilateral DeletionA message is only physically deleted when both sender and recipient have deleted it

Audit Log

All portal actions are logged in a tamper-proof manner:

ActionDescription
sentMessage was sent via the portal
readMessage was read by the recipient
deletedMessage was deleted
attachment_downloadedAn attachment was downloaded

Each entry contains:

  • User ID and email address of the actor
  • IP address of the client
  • Timestamp
  • Details (e.g., integrity check, delivery channel)

The audit log is particularly relevant for compliance evidence (GDPR, NIS2) and serves as non-repudiation proof.

Digest Notifications

Recipients can receive periodic summaries of their portal messages:

SettingDescription
Intervalnever, hourly, daily, weekly
HTML TemplateCustom template with placeholders ({{subject}}, {{rows}}, {{domain}})
LanguageLanguage of the digest email

Advantages

  • No certificate or key management required
  • Ideal for external recipients without their own encryption solution
  • Bidirectional communication via threads
  • Tamper-proof audit log
  • Integrated storage management with quotas
  • Automatic retention policies

Limitations

  • Access for recipients only online via the portal (no offline use)
  • For permanent internal encryption, S/MIME or PGP are better suited
  • Maximum thread depth: 30 messages

Further Documentation

  • Configuration — Activate the portal and set up notifications
  • Delivery Process — How messages are automatically redirected to the portal
  • Replies & Interactions — How recipients reply in the portal

Required Permissions

ActionPermission
View portal messagesOwner, Operator, Analyst, Auditor, Contact
Configure portalOwner, Operator
Manage quarantineOwner, Operator

Auf dieser Seite

  1. Message Portal — Overview
    1. How Does the Portal Work?
    2. Security Features
    3. Threading & Replies
    4. Storage & Quotas
    5. Audit Log
    6. Digest Notifications
    7. Advantages
    8. Limitations
    9. Further Documentation
    10. Required Permissions