Encrypt internalemail inExchange.
Mail between two mailboxes on the same server never reaches a gateway. The Exchange agent changes that: internal messages run through the same rules as external ones. No new addresses, no rebuild.
Why internal mail stays unprotected
Exchange delivers it before any connector applies.
No connector reaches it
Mailbox transport delivers internal messages directly. Send connector and gateway never see them.
Transport rules do not help
The rule action that routes through a connector exists only in Exchange Online, not in your own Exchange.
Rebuilds fail in daily life
Helper domains and second addresses work technically. In daily life everyone still writes to the usual address.
S/MIME per person costs upkeep
Certificates for every mailbox, deployment to every device, regular renewal. And whoever forgets the button sends in clear text.
Mailbox to mailbox, through the gateway.
This is how an internal message travels with the Exchange agent.
No new addresses, no helper domain
The same rules as for external mail
Tracing for every internal message
Deferred instead of clear text on failure
How internal mail runs through the gateway
Three steps, invisible to sender and recipient.
1. The agent spots internal mail
The Exchange agent sits in the transport service. When sender and recipient belong to your own domains, it takes over the message.
2. The gateway applies the rules
SecureMail encrypts by rule with S/MIME, PGP, PDF or portal. The message appears in message tracing.
3. Delivery as usual
The gateway hands the message back to Exchange, and the agent lets it be delivered locally. Nothing changes for the people involved.
Built for operations
Six properties that matter in the data centre.
No clear text on failure
If the gateway is unavailable, the agent defers the message. Exchange retries later, nothing is delivered unprotected.
Original kept until confirmed
The agent discards the original only after the gateway has confirmed the handover. Nothing gets lost on the way.
Observe before switching
At first the agent only logs. Traffic moves to the gateway only once the log shows the right mail.
Transport service stays stable
The agent is not registered as critical. If it fails to load, mail flow continues without it.
Meetings stay untouched
Invitations, cancellations and tasks pass through unchanged. Ordinary messages from Outlook classic are captured in full.
Setup with a double click
The package reads gateway and domains from Exchange and only asks for confirmation. No management shell needed.
Exchange agent or rebuild
The two usual paths to encrypted internal mail.
Exchange agent | Helper domain or S/MIME per person | |
|---|---|---|
| Change addresses and mailboxes | no | yes, or a certificate per person |
| Works without senders thinking about it | yes, by rule | only if everyone remembers |
| Tracing of internal mail | in the portal | not available |
| Certificate upkeep per person | none | for every mailbox |
| Recipients without a key | PDF or portal | no path |
Statements on the alternatives based on the behaviour of Exchange Server SE according to Microsoft product documentation.
Frequently asked questions
How do you encrypt internal email in Exchange Server?
Why does internal mail never reach a gateway?
What happens if the gateway fails?
What are the requirements?
Does this work with Conbool from the cloud?
Do meeting invitations still arrive?
Can the agent bring down the transport service?
Related solutions
Secure Exchange on premises
Filtering, encryption, signatures and archive for Exchange Server SE.
Outlook add-ins for Exchange Server
Five add-ins without Microsoft 365 and without typing a code.
Email security without Entra ID
People, groups and addresses from local Active Directory.
Encryption for Exchange Server
S/MIME, PGP, PDF and portal centrally at the gateway.
Signatures for Exchange Server
Automatic signatures with fields from AD.
See internal mail encrypted
We show the path of an internal message on an Exchange Server SE, from observing to encrypted delivery.