Archiving with a hoster without server access

Archive with All-Inkl, IONOS, Strato and other shared hosters, without a journal rule and without changing the MX: incoming and internal through the copy recipient, outgoing through collection from the mailbox or the mail client.

The usual ways into the archive assume that you may configure something on the mail server: a journal rule in Exchange or Microsoft 365, a BCC rule in Postfix or mailcow. With a shared hoster such as All-Inkl, IONOS or Strato you do not have this access. It still works, with two of the hoster's built-in tools and without touching the MX.

This page describes the way that works without server access. All ways in comparison are listed under ways into the archive.

What is captured by what

The mail flow falls into three parts, and each needs its own source.

Incoming mail is captured through the hoster's copy recipient. At All-Inkl it sits in the settings of every mailbox. The MX stays unchanged.

Internal mail between two mailboxes at the same hoster is an incoming message for the recipient and is therefore captured by the same copy recipient.

Outgoing mail to external recipients is not captured by the copy recipient. There are two ways for it: collection from the sent folder or the copy from the mail client.

Incoming and internal: copy recipient

The assistant under Configuration, card Without a change of the mail flow, guides you through the setup in this order.

  1. Choose the way: in the first step, create a source of the type Copy by BCC and copy the address. The same source sits under Archive, Administration, Sources and migration.
  2. Activate the domain: in the next step of the assistant. Without it the archive assigns the parties to no tenant and discards every copy.
  3. At the hoster: enter the copied address as copy recipient in every mailbox.
  4. Mailboxes and seats: in the assistant, assign seats to the mailboxes and complete the setup.

At All-Inkl the copy recipient can also be set for several mailboxes through the KAS API.

Outgoing, way one: collection from the mailbox

Conbool signs in every fifteen minutes and reads the sent folder. This also captures what went out through webmail or a phone.

  1. Archive, Administration, Sources and migration: click Mailboxes at Collection from the mailbox.
  2. Enter IMAP server and port, then one line per mailbox: address;username;password.

Limit: one set of credentials with full access to the mailbox is required per mailbox. After a password change, collection pauses until the new credentials are stored.

Outgoing, way two: copy from the mail client

In the archive, switch on To mail clients at the source, then generate a code in the card Pair mail clients. The Conbool add-on for Thunderbird sets the copy itself when sending.

Not captured: webmail, phone, computers without the add-on and the blind copy recipients of a message. A user can bypass this way.

Rollout across several computers

For rollout across several computers the setup assistant generates a policies.json with the pairing code filled in under Pair mail clients.

The file belongs on every computer:

  • Windows: C:\Program Files\Mozilla Thunderbird\distribution\policies.json
  • Linux: /etc/thunderbird/policies/policies.json
  • macOS: /Applications/Thunderbird.app/Contents/Resources/distribution/policies.json

It enforces the extension, the user cannot uninstall it, and it pairs itself on first use. Nobody types in a code. The pairing code is valid for seven days and can be redeemed on any number of computers; every computer receives its own token and can be revoked individually.

Keeping the gaps in view

Under Administration, Statistics and system status you find Silent mailboxes: for every assigned mailbox the last receipt in the archive, separated into total and outgoing. A mailbox becomes unusual after 14 days without a message, silent after 30 days or if none ever arrived.

This is where an uninstalled add-on shows up before anyone looks for the missing message. Check there regularly; a mailbox on holiday and a switched-off add-on look the same in the figures, and only you know the difference.

Taking over existing mail

What predates the setup comes in through the import: an .mbox file or a ZIP with .eml files from the mail client's profile, a .pst from Outlook. The import sits under Administration, Sources and migration.

What this way cannot do

Outgoing encryption, signature and disclaimer require the message to pass through the gateway. With a shared hoster it does not. These modules need a mail server whose outbound path can be changed, or mailboxes elsewhere.