Setting up SecureFiles without changing the mail flow

Initial setup of a tenant that uses SecureFiles without mail routing: with its own domain via TXT or Microsoft 365, or without a domain of its own. MX, SPF and DKIM stay untouched.

SecureFiles does not need mail routing through Conbool. The files sit in the tenant's storage, the recipient gets a link, and Conbool sends the notification. MX, SPF and DKIM stay unchanged.

Steps

  1. Open setup: Configuration, "Without mail routing".
  2. Choose the domain option: "Own domain" or "Without your own domain", see below.
  3. Get started: completes the setup.
  4. Invite members: under Members, role "Employee" or higher. Guests cannot send.
  5. Create a rule: under SecureFiles, Rules. Without a matching rule nobody can send.

Own domain

The domain determines which sender addresses count as internal. Ownership is proven in one of two ways:

ProofRequirement
TXT recordRecord _verification.<domain> with the value shown in the interface
Microsoft 365Connected Microsoft 365 tenant in which the domain is verified

Steps for the TXT record:

  1. Enter the domain and choose Enable.
  2. Copy name and value from the "Proof via DNS" box and create them as a TXT record at the DNS provider.
  3. Choose Verify now or Enable again. A new record can take a few minutes to become visible in DNS.

A domain already proven by another tenant cannot be enabled.

Without your own domain

For mailboxes without a domain of their own, for example freemail addresses. Offered only if no module other than SecureFiles and Archive is booked. If a module that needs a domain is added later, the sidebar leads back into setup.

A member can send when all conditions are met:

  • The address was confirmed at sign-in, and exactly this address is used to send.
  • The role carries the send permission. Guests do not have it.
  • An active rule covers the member.
  • The domain of the address is not proven by any tenant. Addresses of another tenant's proven domain do not count.

Limitation: the Outlook add-in identifies the tenant only through its own domain or a Microsoft 365 connection. Without either, sending runs through the portal in the browser.

Rules

  • All tenant users: one rule for all members is enough, every new member can send right after accepting the invitation.
  • Single user: "Select" lists the tenant's members and the users from the directory. The address can also be typed in before the invitation is accepted.
  • Group: for a group of the tenant.

A member with the send permission who is not covered by a rule sees the notice "Not yet allowed to send" under SecureFiles.

Seats and storage

  • Seats: Conbool assigns them automatically from the quota on first send. If manual seat assignment is active, the administrator assigns them.
  • Storage: Conbool storage unless configured otherwise. Your own S3-compatible storage can be added under Settings, SecureFiles, see storage and quota.

What is different without mail routing

  • The notification to the recipient comes from a Conbool address, not from your own domain.
  • Conbool does not see the tenant's mail traffic. Modules that rely on the mail flow are not available.