Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Scanning E-mail traffic with "Hosted Exchange" ?

Hi,

we will change our e-mail system from POP3/SMTP to "Hosted Echange" (Exchange cloud mailboxes).

Is it possible to use the E-Mail protection to scan incoming and outgoing E-mail traffic ?

Or must we have an internal Exchange/Mailserver ?

Thanks for your help.



This thread was automatically locked due to age.
Parents
  • Hi Gooni,

    Are you asking if you can scan the flow of emails between your client devices and your Cloud email host, presuming it's Office365 or an Azure Exchange Server?

    If so, then that would be a yes and a no. Connection to exchange is done over HTTPS so that would fall under HTTPS decrypt and scan settings. And no the email scanning engine cannot be used to intercept the flow of communications between client and Exchange unless emails were being sent over POP3/SMTP (unlikely unless you have a hybrid setup).

    However, what you can do is set up the XG as a mail transport agent between the internet and your cloud email host which would be as the following:

    • Incoming email: Internet > XG > Send email out to Cloud Email Provider
    • Outgoing email: Cloud Email Provider pushes email as outgoing relay > XG sends email out to the internet as itself > Internet

    This is far better served on v16 where you have the full capability of configuring the XG as a Mail Transport Agent wherein the XG becomes another hop in the chain of the incoming/outgoing mail delivery.

    Is that what you were asking?

    Emile

  • Hi,

    Thanks for your answers.  Our  Exchange Provider would be 1und1  (a german provider). If i have understood  correctly, then I cant scan and drop Mails.

Reply Children
  • Hi Gooni,

    Ah, if it's 1&1 then you will be connecting to them via IMAP/POP3 in which case you can do transparent scanning between client and MailServer but for best results you will have to purchase an SSL Certificate from a third party (recommend GoDaddy as they're generally the cheapests).

    In addition to Adityas post, the Knowledgebase article which tells you all this (and is very short) is here:

    https://community.sophos.com/kb/en-us/123274

    Hope that helps! And by the way, avoid calling your MailServer that's hosted by 1&1 as Exchange as that name is generally used for the Microsoft Product Exchange and can cause confusion :)

    Emile