Offboarding: removing Conbool cleanly
The full rollback at the end of a contract: MX, SPF, connector, transport rule and Entra applications, plus the deletion periods for the data we hold.
This page describes the rollback. It exists because the question belongs in every tender, and because a provider who does not document the exit makes the entrance harder than it needs to be.
The rollback takes about an hour and needs no call with us. We recommend the order below: it keeps mail flowing at every step.
1. Route inbound mail back
Start with the MX, because everything else hangs off it.
- Point the MX of your domain back at your target system, for Microsoft 365 that is
your-domain-com.mail.protection.outlook.com. - Wait out the TTL of the old record, usually an hour. Until then Conbool keeps accepting mail and delivers it to your system.
- Check with
dig MX your-domain.comthat the new record is visible everywhere.
Only then the remaining steps. Removing the connector first blocks the mail still sitting with us.
2. Clean up SPF
Remove include:mail.conbool.com and, if you sent through us, include:mx01.conbool.com from the SPF record of your domain. Leave the rest untouched; an SPF without your own target system breaks sending.
3. Roll back Microsoft 365
If you used the guided path, Conbool created three things in your tenant:
| Object | Where | Rollback |
|---|---|---|
| Inbound connector | Exchange Admin Center, Mail flow, Connectors | delete |
| Transport rule for marking | Exchange Admin Center, Mail flow, Rules | delete |
| Connection filter with our address | Defender portal, Policies, Anti-spam | remove the address |
If you enabled RejectDirectSend on our recommendation, decide for yourself whether it stays. It is useful independently of Conbool.
4. Withdraw the Entra applications
Conbool uses up to three registrations. Remove them in the Entra portal under Enterprise applications by deleting the application:
| Application | What it could do |
|---|---|
| Conbool Provisioner | create the connector and transport rule, read the directory |
| Conbool Mailbox Write | write and delete messages in mailboxes, read inbox rules |
| Conbool Backup | only with 365 Backup booked |
After deletion Conbool has no technical access to your tenant. That takes effect immediately, not when some token expires.
5. Your data with us
| What | Period |
|---|---|
| Message tracing and quarantine | per the retention you configured, at most 30 days after the contract ends |
| Quarantine copies and cleaned originals | with the tracing, same period |
| Configuration, policies, lists | 30 days after the contract ends |
| Logs of administrative actions | as agreed in the data processing agreement |
| Archive under a WORM period | unchanged until the statutory period expires, that is the point of the archive |
A daily run removes the data of an ended contract once the period has passed. You do not need to do anything or ask for it.
6. Before that: take your data with you
Before the periods bite, export what you want to keep:
- Message tracing as CSV from the tracing view, any period.
- Archive through the archive module's export, if booked.
- Configuration through the configuration package in the settings.
For a full data export outside these paths, a mail to support is enough; it is part of the contract and costs nothing.
What we do not do
We do not hold data back to make a rollback harder, and we charge nothing for the export. There is no notice period for the technical rollback: you can switch the MX at any time, including in the middle of a contract term.