Offboarding: removing Conbool cleanly

The full rollback at the end of a contract: MX, SPF, connector, transport rule and Entra applications, plus the deletion periods for the data we hold.

This page describes the rollback. It exists because the question belongs in every tender, and because a provider who does not document the exit makes the entrance harder than it needs to be.

The rollback takes about an hour and needs no call with us. We recommend the order below: it keeps mail flowing at every step.

1. Route inbound mail back

Start with the MX, because everything else hangs off it.

  1. Point the MX of your domain back at your target system, for Microsoft 365 that is your-domain-com.mail.protection.outlook.com.
  2. Wait out the TTL of the old record, usually an hour. Until then Conbool keeps accepting mail and delivers it to your system.
  3. Check with dig MX your-domain.com that the new record is visible everywhere.

Only then the remaining steps. Removing the connector first blocks the mail still sitting with us.

2. Clean up SPF

Remove include:mail.conbool.com and, if you sent through us, include:mx01.conbool.com from the SPF record of your domain. Leave the rest untouched; an SPF without your own target system breaks sending.

3. Roll back Microsoft 365

If you used the guided path, Conbool created three things in your tenant:

ObjectWhereRollback
Inbound connectorExchange Admin Center, Mail flow, Connectorsdelete
Transport rule for markingExchange Admin Center, Mail flow, Rulesdelete
Connection filter with our addressDefender portal, Policies, Anti-spamremove the address

If you enabled RejectDirectSend on our recommendation, decide for yourself whether it stays. It is useful independently of Conbool.

4. Withdraw the Entra applications

Conbool uses up to three registrations. Remove them in the Entra portal under Enterprise applications by deleting the application:

ApplicationWhat it could do
Conbool Provisionercreate the connector and transport rule, read the directory
Conbool Mailbox Writewrite and delete messages in mailboxes, read inbox rules
Conbool Backuponly with 365 Backup booked

After deletion Conbool has no technical access to your tenant. That takes effect immediately, not when some token expires.

5. Your data with us

WhatPeriod
Message tracing and quarantineper the retention you configured, at most 30 days after the contract ends
Quarantine copies and cleaned originalswith the tracing, same period
Configuration, policies, lists30 days after the contract ends
Logs of administrative actionsas agreed in the data processing agreement
Archive under a WORM periodunchanged until the statutory period expires, that is the point of the archive

A daily run removes the data of an ended contract once the period has passed. You do not need to do anything or ask for it.

6. Before that: take your data with you

Before the periods bite, export what you want to keep:

  • Message tracing as CSV from the tracing view, any period.
  • Archive through the archive module's export, if booked.
  • Configuration through the configuration package in the settings.

For a full data export outside these paths, a mail to support is enough; it is part of the contract and costs nothing.

What we do not do

We do not hold data back to make a rollback harder, and we charge nothing for the export. There is no notice period for the technical rollback: you can switch the MX at any time, including in the middle of a contract term.