After the outage: how the mail catches up
How Conbool delivers the caught messages once the mail server answers again, how long it takes and when a message is rejected after all.
Conbool recognises the recovery at the same place where it recognised the outage: in the answers of the target system. Two successful deliveries in a row are enough, and the domain counts as reachable again.
From that moment the catch-up delivery starts by itself. There is nothing to confirm and nothing to release.
The order
Delivery catches up in the order of arrival, oldest first. Afterwards the mailbox shows the same sequence as without an outage, only with a delay.
The time shown in the mailbox stays that of the actual arrival at Conbool. A message that arrived at 09:12 and was delivered at 11:40 still carries 09:12. Anyone sorting mail by date therefore finds it where they expect it.
How long it takes
After recovery all waiting messages are due immediately, and the catch-up works without a pause until nothing is left. For the usual volumes of a working day that is minutes.
During the outage itself a different rhythm applies. There, delivery is retried at growing intervals, starting at two minutes and ending at six hours. That keeps the load away from the failed system, which is supposed to be recovering.
Duplicate delivery
A message is only marked once the target system has accepted it. If the connection drops in the middle of a delivery, it counts as not delivered and is attempted again. In that rare case a message can arrive twice.
That is intentional. The alternative would be not to deliver when in doubt, and a duplicate message is far less harmful than a missing one.
If the target does not come back
After five days Conbool gives up. The sender then receives a non-delivery report stating that the message could not be delivered.
Five days is deliberately longer than the usual periods of delivering servers. Whoever took the message over at level 2 should not give up on it earlier than the party that would otherwise have held it.
While the period is running, the message stays readable in the continuity view. It is therefore not lost even if delivery never succeeds.
Clearing up
The continuity store keeps the messages for the configured retention time and deletes them afterwards, regardless of whether they were delivered. At that point the delivered message sits in the actual mailbox and, where present, in the archive.
The continuity store is not an archive and not a backup. It is the stopover for the duration of the disruption.
What tells you about the outage later
Every outage is recorded with start, end, duration and the number of messages caught. That record sits in the continuity overview and answers the question that always comes after a disruption: how long was it, and what did it catch.