Setting up SecureFiles without changing the mail flow
Initial setup of a tenant that only uses SecureFiles. Domain by proof of ownership, choose storage, assign seats. MX, SPF and DKIM stay untouched.
SecureFiles runs alongside the mailbox: the files sit in the tenant's storage, the recipient gets a link, and Conbool sends the notification. Mail traffic does not have to run through Conbool for that. A tenant that has only booked SecureFiles therefore skips the delivery wizard with MX, SPF and DKIM.
The path in five steps
1. Add the domain with proof of ownership
Under setup, two paths lead on. The second is called "Without changing the mail flow" and creates a domain that only proves its owner and stays irrelevant for mail sending.
Ownership is proven in two ways:
- If the domain is already verified in a connected Microsoft 365 tenant, the connection is enough and no DNS record is needed.
- Otherwise a TXT record is checked. The interface names the record and value when the domain is added.
MX, SPF and DKIM stay unchanged in both cases. The domain decides who counts as an internal user of the tenant and which sender addresses SecureFiles accepts.
2. Choose the storage
Under settings and then SecureFiles sits the storage. The storage of Conbool and an S3-compatible storage of your own are available, for instance at STACKIT, IONOS or Hetzner. Your own storage stays in the responsibility of the tenant, Conbool only writes and reads the files of the transfers in it.
3. Assign seats
Under settings and then licences the members receive their seats. Only with a seat can a member send transfers. Recipients outside the tenant need neither a seat nor an account.
4. Create a rule that permits sending
SecureFiles works on the allowlist model: without a rule nobody may send. Under SecureFiles and then rules the first rule is created, in the simplest case for all users of the tenant and without restrictions. It can be made finer per user or per group, and expiry, mandatory passwords and permitted recipient domains can be set there as well.
5. Optionally roll out the Outlook add-in
Anyone who wants to send from Outlook rolls out the add-in through the Microsoft 365 admin center. Without the add-in, sending runs through the interface, see sending files.
What is different without mail flow
The notification to the recipient is sent by Conbool from its own delivery. The sender is therefore a Conbool address and not an address of your own domain. The link, the password and the expiry are unaffected by that.
Incoming mail traffic is likewise unaffected: without a changed mail flow Conbool sees no messages of the tenant, and modules that build on the mail flow are not available.