Email signature without changing the mail flow

Central signature management purely through the Outlook add-in: no MX change, no SPF or DKIM record and no installation of your own on site.

Not every company wants to route its mail traffic through another service provider. For that case, central signature management can be used purely through the Outlook add-in. The messages stay entirely in Microsoft 365, while the templates and their assignment remain centrally in the administration interface.

What is different

In regular operation the server appends the signature at send time. Without mail flow the add-in takes over that job in the mailbox: while a message is being written it applies the released signature, and for replies and forwards the version stored for those. The content of the message never leaves Microsoft 365.

Prerequisites

  • Microsoft 365 with a connected Entra ID. Through that connection the add-in recognises the tenant and fills the placeholders from the directory.
  • Central deployment of the add-in through the Microsoft 365 admin center. Only centrally assigned add-ins apply the signature without a click.
  • Outlook as the mail program, on the web, on Windows, on the Mac and on the smartphone.

Not needed are an MX change, an SPF record pointing at Conbool, a DKIM key from Conbool and an installation on your own premises.

Releasing the domain

The domain is registered without delivery rights. Proof that it belongs to the tenant is enough.

  1. In the settings, open the Disclaimer area and choose the add-in deployment there.
  2. Under "Domain without mail flow", enter the domain and release it.
  3. If the domain is already verified in the connected Microsoft 365 tenant, the proof is thereby provided and no DNS record is needed. Otherwise a TXT record is checked, which the interface shows with its name and value.

A domain released this way is valid for the add-in only. It permits no delivery through Conbool and changes neither SPF nor DKIM nor the MX record.

Setup in five steps

  1. Connect Entra ID and synchronise the directory.
  2. Release the domain as described above.
  3. Create templates in the signature editor and release them for the add-in.
  4. Assign mailboxes in the licence management.
  5. Roll out the add-in through the admin center.

Signature on replies

For replies and forwards three options are available: the same signature as on the first message, no signature, or a separate short template per language. If the short template is missing for a language, the full signature is used there. If nothing is appended, a signature set up in the mailbox itself stays untouched.

Limits of this mode

These points belong on the table before deciding:

  • No enforcement. The signature is created in the mailbox and can be deleted or changed there. Anyone who needs an unalterable line on every outgoing message, for instance for the statutory footer under section 37a HGB, needs the server-side path.
  • Outlook only. Other mail programs and devices that send directly through Microsoft 365 receive no signature.
  • Mailboxes in Exchange Online only. The add-in signs in with a token issued by Microsoft and applies the signature through an event handler that does not exist in Exchange on-premises. For in-house mailboxes the path runs through a send connector, see connecting Exchange on-premises. In a hybrid environment the distinction applies per mailbox.
  • No rules, banners and campaigns. The rule set with building blocks for banner, campaign and legal text, with periods and recipient conditions, is evaluated by the server. Through the add-in, signature templates per language are available including group visibility and template choice per mailbox.
  • Incoming messages stay untouched. Without mail flow there is no processing of incoming mail.

Data protection

Message content is not transferred to Conbool in this mode. What is processed is the directory data that fills the placeholders, that is name, function, phone number and comparable details from Entra ID, plus the sender address when the signature is fetched. Images in a signature are loaded from the Conbool servers at the recipient.

Moving to the mail flow later

The switch is possible without rebuilding. If the domain is set up regularly later, the server takes over the signature and the add-in remains as a preview and template picker. Duplicate signatures do not arise: a message the add-in has already worked on is not processed a second time server side.

Continue to deploying the add-in. Back to the category overview central email signatures.