Exchange agent: routing internal mail through the gateway

Encrypt and trace internal email between mailboxes on the same Exchange Server. Setup, operating modes, behaviour when the gateway is unavailable, exceptions and updates.

A message from one mailbox to another mailbox on the same Exchange never leaves the server. Mailbox transport delivers it directly, before a send connector is ever chosen. No accepted domain and no transport rule changes that, because the rule action that routes through a connector only exists in Exchange Online.

Internal mail therefore never reaches a gateway. It is neither encrypted nor captured in message tracing. The Exchange agent closes that gap without changing mailboxes, addresses or domains.

How the agent works

The agent is a transport agent in the transport service of the Exchange Server. When sender and recipient belong to the configured domains, it hands the message to the Conbool gateway over SMTP. It discards the original only after the gateway has confirmed the handover.

The gateway applies the rules that apply to external mail as well, such as SecureMail with PDF, portal, S/MIME or PGP, and delivers the message back to Exchange. The agent recognises its marker and lets the message be delivered locally.

Requirements

  • An Exchange Server with the mailbox role. Tested with Exchange Server SE.
  • A Conbool installation in your own network. The gateway identifies internal mail by its private source address.
  • The gateway is reachable from Exchange over SMTP on port 25.
  • The domains are verified in Conbool, and the mail server of the domain points to Exchange.

Setup

  1. In the portal under Settings, Agents, Mail agent, download the installation package.
  2. Run the package on the Exchange Server. After installation the setup dialog opens.
  3. Confirm gateway and domains. The gateway is prefilled, first with the address from the package, then with the MX of the accepted domains, last with the smart host of the send connectors. The domains come from the accepted domains of Exchange.
  4. Start with the mode Beobachten, which only observes. The dialog is in German and restarts the transport service after asking.

On first launch Windows SmartScreen may show a notice about the publisher.

Operating modes

Beobachten, observe. Internal mail is logged, the mail flow stays unchanged. This shows whether the agent picks up the right messages.

Über das Gateway führen, route through the gateway. Internal mail is handed to the gateway and delivered from there. Switch only once the log shows the internal mail.

When the gateway is unavailable

The agent defers the message, and Exchange retries it later. There is no unprotected delivery, because a message delivered in clear text cannot be recalled.

If the gateway rejects a message permanently, the sender receives a non-delivery report.

Exceptions

  • Meetings, cancellations and tasks pass through unchanged. Outlook wraps them in its own format, which does not survive a conversion intact.
  • System messages such as non-delivery reports pass through unchanged.

Ordinary messages from Outlook classic are captured, even though Outlook sends them internally in its own format.

Safety of the transport service

Exchange registers a newly installed agent as critical. A critical agent that fails to load prevents the whole transport service from starting. Setup removes that flag: if the agent does not load, mail flow continues without it.

Verify

Send a message between two internal mailboxes. Expected:

  • The message appears in the portal under Message tracing.
  • The message arrives, handled as the SecureMail rules define.

Update, disable, remove

A new package is installed over the existing one. Settings are kept.

Abschalten in the dialog keeps the agent installed but idle. That is the path during an incident. Entfernen unregisters the agent from the transport service.