SecureMail · Exchange Server SE

Email encryptionfor Exchange Server.Central, not per client.

S/MIME, PGP, PDF and portal by rule, at the gateway instead of in every Outlook. Outbound encrypted, inbound decrypted. Users send as usual.

Why S/MIME on Exchange struggles in practice

Four reasons from the field.

A certificate per person

Every mailbox needs its own certificate, deployed to every device and renewed regularly.

Recipients without a key

Without a certificate a recipient can read nothing. Exchange brings no second path for them.

Encryption is manual work

The button in Outlook depends on people. One forgotten setting and the message goes out in clear text.

No central evidence

Exchange does not show in one place whether a message went out encrypted. The audit is left without an answer.

How SecureMail encrypts on Exchange

One send connector, rules in the portal.

1. Send connector to the gateway

Outbound mail runs through a send connector to Conbool. For outbound encryption the MX stays unchanged.

2. Method per recipient

If the recipient has S/MIME or PGP, that is used. Otherwise the message goes as a protected PDF or through the portal.

3. Decrypt inbound

With the MX at the gateway, SecureMail decrypts inbound mail before it lands in the mailbox.

Exchange Server SE · SecureMail
Exchange Server SE
Send connector with enforced TLS
Smart host
SecureMail
Rule per recipient
S/MIME
PGP
PDF
Portal
Outbound
encrypted to the recipient
Inbound
decrypted into the mailbox
Internal mail additionally through the Exchange agent
Mail path

From Exchange to the recipient.

Exchange sends as before. The gateway decides per recipient.

No certificate in the client

Method per recipient, automatically

Inbound decrypted when the MX points to the gateway

Tracing for every message

What SecureMail does on Exchange Server

Six points for in-house operation.

S/MIME and PGP centrally

Keys and certificates live at the gateway, not in every client.

PDF and portal for everyone else

Recipients without a key read in a protected PDF or in the message portal.

Internal mail with the Exchange agent

Messages between two mailboxes on the same server run through the rules as well.

Add-in without Microsoft 365

Choose the method in the Outlook add-in, with a manifest for Exchange Server and pairing without typing a code.

Evidence per message

Message tracing and delivery receipts show how each message was handled.

In your own data centre

SecureMail runs from EU data centres or as an installation in your own building.

S/MIME in Outlook or SecureMail

Two paths to encrypted mail on Exchange Server.

 
SecureMail at the gateway
S/MIME in the Outlook client
Certificate on every device
not needed
required
Recipients without a key
PDF or portal
no path
Enforce encryption
by rule
setting per client
PGP
yes
not included
Central evidence
in the portal
not available

Statements on Outlook based on Microsoft product documentation.

Frequently asked questions

How do you encrypt email on Exchange Server?
With S/MIME in the client or centrally through a gateway. SecureMail takes the second path: a send connector routes outbound mail through Conbool, where it is encrypted by rule.
Do I need S/MIME certificates for every person?
No. SecureMail manages certificates and keys at the gateway. For recipients without a key there are PDF and portal.
Does the MX have to change?
Not for outbound encryption. To decrypt inbound mail, the MX runs through the gateway.
Is internal email encrypted?
With the Exchange agent, yes. Without it, mail between two mailboxes on the same server never reaches a gateway.
Is there an Outlook add-in for Exchange Server?
Yes, with a dedicated manifest for Exchange Server. It runs without Microsoft 365 and pairs without typing a code.
Which Exchange versions are supported?
The send connector path works with any Exchange that can send through a smart host. Exchange agent and add-ins are tested with Exchange Server SE.

Related solutions

See SecureMail on your own Exchange

A demo on an Exchange SE environment, from the send connector to the encrypted message at the recipient.