Addresses and allowlisting: what goes into the firewall and the connector

The hostnames and IP addresses of Conbool for MX, SPF, firewall rules and the Exchange connector, and which of them may change.

This page answers the question that comes up in every setup and was in none of our guides: which addresses do I put into the firewall, into the Exchange connector and into the SPF record.

Names, not addresses

Wherever names are allowed, enter the hostname, not the IP address. Names stay valid when we replace a node; a hard-coded IP address does not.

PurposeEntry
MX of your domainmail.conbool.com
SPF of your domaininclude:mail.conbool.com
Exchange connector, inboundmail.conbool.com
Outbound path through Conboolmx01.conbool.com
SPF for the outbound pathinclude:mx01.conbool.com
Web interface and portalconbool.com

Addresses for the firewall

Only where names are not possible, for instance in a packet filter rule:

HostIPv4Purpose
mail.conbool.com217.160.214.251accepting your inbound mail, port 25
mx01.conbool.com85.215.68.218sending your mail through Conbool, port 25

IPv6 is currently not offered for delivery. Both addresses appear in the SPF records of the respective hostnames, and that is the authoritative source: dig TXT mail.conbool.com answers the question at any time and is more current than any documentation page.

What you need to allow, and what you do not

  • Inbound, your mail server must accept connections from mail.conbool.com on port 25. If you open the port only for known addresses, enter the address from the table.
  • Outbound, you need no rule for us. Conbool connects to you, not the other way round.
  • For the portal and the add-ins, ordinary HTTPS traffic to conbool.com is enough. No dedicated port, no fixed address.

If something changes

We announce a change to these addresses in advance and keep the old address running during the switch. Anyone who entered names has nothing to do. Anyone who entered addresses gets the announcement at the administrative address stored in the tenant.