Ways into the archive: with and without the mail flow
Overview of every way messages reach the Conbool archive: gateway, journal rule, BCC rule, copy recipient at the hoster, collection from the mailbox and copy from the mail client, with instructions and limits.
The goal of archiving is simple: every message belongs in the archive, incoming, outgoing and ideally internal mail from mailbox to mailbox as well. Which way fits depends on a single question.
The question first: does the mail flow run through Conbool?
If the MX of your domain points to Conbool and outgoing mail leaves through us, we see every message anyway. If the mail flow stays with your current provider, the archive needs a copy, and that copy can come from four different sources.
All ways at a glance
| Way | Captures | Does not capture | Requirement |
|---|---|---|---|
| Gateway | incoming and outgoing, with Microsoft 365 internal as well | internal mail outside Microsoft 365, internal calendar traffic | MX on Conbool, sending through us |
| Journal rule | everything, internal included | nothing | Exchange or Microsoft 365 |
| BCC rule in the mail server | everything, internal included | blind copy recipients without address extension | access to the server configuration |
| Copy recipient at the hoster | incoming and internal | outgoing mail to external recipients | the hoster offers the function |
| Collection from the mailbox | inbox and sent items | custom folders, messages deleted before the run | credentials per mailbox |
| Copy from the mail client | outgoing and internal from this client | webmail, phone, other computers, Outlook, Apple Mail, blind copy recipients | Thunderbird with the Conbool add-on |
The ways can be combined. No duplicates arise: the archive recognises them by the Message-ID and stores each one only once.
With the mail flow through Conbool
The standard case. Once the mail flow is set up, Conbool archives what comes in and goes out without any further action.
Internal mail with Microsoft 365: it runs through the gateway as well and is archived. The outbound rule from the connector setup applies to every message from a sender in your domain, whether the recipient sits inside or outside. Only what the rule explicitly excludes stays out: calendar traffic and non-delivery reports.
Limit: with Exchange on premises, your own mail server and mailboxes at a hoster, internal mail stays local and never reaches the gateway. There the mail server delivers internally before a connector or the MX is even consulted. Anyone who needs it in the archive adds a journal rule or a BCC rule.
Without the mail flow through Conbool
MX, SPF and DKIM remain untouched. In all four cases the assistant under Configuration, card Without a change of the mail flow, guides you through the same sequence: first choose the way and create the source, then activate the domain, then mailboxes and seats. The same sources remain available permanently under Archive, Administration, Sources and migration. Without the activated domain the archive cannot assign the parties to a tenant and discards every copy.
Journal rule in Exchange or Microsoft 365
The journal report contains the message and the envelope parties, meaning sender and recipients from the transport.
- Create a source of the type Exchange journal rule and copy the address.
- In the Exchange admin center under mail flow, create a journal rule with this address as journal recipient and all messages as scope.
BCC rule in your own mail server
For Postfix, mailcow, Zimbra and every server whose configuration is open to you.
- Create a source of the type Copy by BCC.
- In the mail server, set a rule that sends a copy to this address, for example
always_bccorrecipient_bcc_maps.
The recommended form uses an address extension, <token>+<user>=<domain>@journal.conbool.com. Only this way are blind copy recipients captured as well.
Copy recipient at the hoster
Many hosters, All-Inkl among them, offer a copy recipient per mailbox. It works without access to the server configuration.
- Create a source of the type Copy by BCC and copy the address.
- At the hoster, enter this address as copy recipient in the settings of every mailbox.
Limit: the copy recipient only applies to incoming messages. Internal mail is captured because it is incoming for the recipient; outgoing mail to external recipients is not.
Collection from the mailbox
Conbool signs in to every mailbox every fifteen minutes and reads the inbox and sent items. This way needs no action from users and also captures mail from webmail and mobile devices.
- Under Archive, Administration, Sources and migration, click Mailboxes at Collection from the mailbox.
- Enter IMAP server and port, then one line per mailbox:
address;username;password. The username may stay empty if it matches the address.
Limit: one set of credentials per mailbox is required. It grants full access to the mailbox, not only reading. After a password change, collection pauses until the new credentials are stored. Very few hosters offer a shared access.
Copy from the mail client
The Conbool add-on for Thunderbird fetches the ingestion address and sets it as an invisible copy when sending.
- At the source, switch on To mail clients.
- In the card Pair mail clients, generate a pairing code and load the add-on.
- Install the add-on in Thunderbird and pair it with the code.
For rollout across several computers a policies.json is available. It installs the extension as a default and pairs it without entering a code.
Limit: only what leaves this one mail client is captured. The hoster's webmail, a phone, a second computer without the extension as well as Outlook and Apple Mail stay outside, as do a message's blind copy recipients. Without policies.json the user can deactivate the extension.
Recommendation by starting point
Your own mail server or Exchange on premises: journal rule or BCC rule. One way, everything captured.
Microsoft 365 with the mail flow through Conbool: already complete except for internal calendar traffic. Anyone who needs that in the archive too adds a journal rule.
Mailboxes at a shared hoster: copy recipient for incoming and internal, plus collection for the sent folder. Where passwords are out of the question, the add-on takes their place, with the limitation described.
What is never captured
Blind copy recipients of a message appear in no header. Without an address extension in the BCC rule the archive does not know them.
Messages from before the setup do not arrive by themselves. For that there is the import from PST, MBOX or EML under Administration, Sources and migration.
Checking that it runs
Under Administration, Statistics and system status you find Silent mailboxes: for every mailbox with an archive seat the last receipt, separated into total and outgoing. A mailbox counts as unusual after 14 days without a message, as silent after 30 days or without any receipt at all.
The display does not distinguish between an unused mailbox and a switched-off source. A regular check is therefore part of operations.