Setting up SecureFiles without changing the mail flow
Initial setup of a tenant that uses SecureFiles without mail routing: with its own domain via TXT or Microsoft 365, or without a domain of its own. MX, SPF and DKIM stay untouched.
SecureFiles does not need mail routing through Conbool. The files sit in the tenant's storage, the recipient gets a link, and Conbool sends the notification. MX, SPF and DKIM stay unchanged.
Steps
- Open setup: Configuration, "Without mail routing".
- Choose the domain option: "Own domain" or "Without your own domain", see below.
- Get started: completes the setup.
- Invite members: under Members, role "Employee" or higher. Guests cannot send.
- Create a rule: under SecureFiles, Rules. Without a matching rule nobody can send.
Own domain
The domain determines which sender addresses count as internal. Ownership is proven in one of two ways:
| Proof | Requirement |
|---|---|
| TXT record | Record _verification.<domain> with the value shown in the interface |
| Microsoft 365 | Connected Microsoft 365 tenant in which the domain is verified |
Steps for the TXT record:
- Enter the domain and choose Enable.
- Copy name and value from the "Proof via DNS" box and create them as a TXT record at the DNS provider.
- Choose Verify now or Enable again. A new record can take a few minutes to become visible in DNS.
A domain already proven by another tenant cannot be enabled.
Without your own domain
For mailboxes without a domain of their own, for example freemail addresses. Offered only if no module other than SecureFiles and Archive is booked. If a module that needs a domain is added later, the sidebar leads back into setup.
A member can send when all conditions are met:
- The address was confirmed at sign-in, and exactly this address is used to send.
- The role carries the send permission. Guests do not have it.
- An active rule covers the member.
- The domain of the address is not proven by any tenant. Addresses of another tenant's proven domain do not count.
Limitation: the Outlook add-in identifies the tenant only through its own domain or a Microsoft 365 connection. Without either, sending runs through the portal in the browser.
Rules
- All tenant users: one rule for all members is enough, every new member can send right after accepting the invitation.
- Single user: "Select" lists the tenant's members and the users from the directory. The address can also be typed in before the invitation is accepted.
- Group: for a group of the tenant.
A member with the send permission who is not covered by a rule sees the notice "Not yet allowed to send" under SecureFiles.
Seats and storage
- Seats: Conbool assigns them automatically from the quota on first send. If manual seat assignment is active, the administrator assigns them.
- Storage: Conbool storage unless configured otherwise. Your own S3-compatible storage can be added under Settings, SecureFiles, see storage and quota.
What is different without mail routing
- The notification to the recipient comes from a Conbool address, not from your own domain.
- Conbool does not see the tenant's mail traffic. Modules that rely on the mail flow are not available.