SecureMail · Exchange agent

Encrypt internalemail inExchange.

Mail between two mailboxes on the same server never reaches a gateway. The Exchange agent changes that: internal messages run through the same rules as external ones. No new addresses, no rebuild.

Why internal mail stays unprotected

Exchange delivers it before any connector applies.

No connector reaches it

Mailbox transport delivers internal messages directly. Send connector and gateway never see them.

Transport rules do not help

The rule action that routes through a connector exists only in Exchange Online, not in your own Exchange.

Rebuilds fail in daily life

Helper domains and second addresses work technically. In daily life everyone still writes to the usual address.

S/MIME per person costs upkeep

Certificates for every mailbox, deployment to every device, regular renewal. And whoever forgets the button sends in clear text.

Exchange Server SE · internal message
Mailbox A
Human resources
Mailbox B
Management
Direct delivery without gateway
Exchange agent
spots internal mail in the transport service
SMTP to the gateway
Conbool gateway
in your own network
SecureMail rule applied
Encrypted by rule
Listed in message tracing
back to Exchange
Delivered to mailbox B
Gateway down: deferred
Message path

Mailbox to mailbox, through the gateway.

This is how an internal message travels with the Exchange agent.

No new addresses, no helper domain

The same rules as for external mail

Tracing for every internal message

Deferred instead of clear text on failure

How internal mail runs through the gateway

Three steps, invisible to sender and recipient.

1. The agent spots internal mail

The Exchange agent sits in the transport service. When sender and recipient belong to your own domains, it takes over the message.

2. The gateway applies the rules

SecureMail encrypts by rule with S/MIME, PGP, PDF or portal. The message appears in message tracing.

3. Delivery as usual

The gateway hands the message back to Exchange, and the agent lets it be delivered locally. Nothing changes for the people involved.

Built for operations

Six properties that matter in the data centre.

No clear text on failure

If the gateway is unavailable, the agent defers the message. Exchange retries later, nothing is delivered unprotected.

Original kept until confirmed

The agent discards the original only after the gateway has confirmed the handover. Nothing gets lost on the way.

Observe before switching

At first the agent only logs. Traffic moves to the gateway only once the log shows the right mail.

Transport service stays stable

The agent is not registered as critical. If it fails to load, mail flow continues without it.

Meetings stay untouched

Invitations, cancellations and tasks pass through unchanged. Ordinary messages from Outlook classic are captured in full.

Setup with a double click

The package reads gateway and domains from Exchange and only asks for confirmation. No management shell needed.

Exchange agent or rebuild

The two usual paths to encrypted internal mail.

 
Exchange agent
Helper domain or S/MIME per person
Change addresses and mailboxes
no
yes, or a certificate per person
Works without senders thinking about it
yes, by rule
only if everyone remembers
Tracing of internal mail
in the portal
not available
Certificate upkeep per person
none
for every mailbox
Recipients without a key
PDF or portal
no path

Statements on the alternatives based on the behaviour of Exchange Server SE according to Microsoft product documentation.

Frequently asked questions

How do you encrypt internal email in Exchange Server?
With S/MIME certificates for every person or through a gateway. Because internal mail normally never reaches the gateway, the second path needs a transport agent. Conbool ships one.
Why does internal mail never reach a gateway?
Exchange delivers messages between mailboxes of the same organisation directly, before a send connector is chosen. The rule action that routes through a connector exists only in Exchange Online.
What happens if the gateway fails?
The agent defers the message, and Exchange retries later. There is no unprotected delivery. If the gateway rejects a message permanently, the sender receives a non-delivery report.
What are the requirements?
An Exchange Server with the mailbox role, tested with Exchange Server SE, and a Conbool installation in your own network that Exchange reaches over SMTP.
Does this work with Conbool from the cloud?
Not for internal mail. The gateway recognises internal messages by their origin in your own network, so it belongs there. Encryption and signatures for external mail also run from the cloud.
Do meeting invitations still arrive?
Yes. Meetings, cancellations and tasks pass through unchanged. Ordinary messages from Outlook classic are captured, even though Outlook sends them internally in its own format.
Can the agent bring down the transport service?
No. Setup removes the critical agent flag. If the agent fails to load, mail flow continues without it.

Related solutions

See internal mail encrypted

We show the path of an internal message on an Exchange Server SE, from observing to encrypted delivery.