Instructions for Configuring Microsoft
Exchange 2007/2010 for smarshEncrypt
Versions Addressed: Microsoft Exchange 2007/2010 Document Updated: March 25, 2015
Confidential | Copyright © 2015Smarsh, Inc. All rights reserved.
Purpose: This document will assist the end user in configuring smarshEncryptfor Microsoft Exchange 2007/2010.
Navigate to the Send Connector configuration area ... 3
Add a new Send Connector for using Encryption only ... 4
Add new Journaling Send Connector for Encryption with existing Journaling rule ... 9
Add new Encryption Send Connector for Encryption with existing Journaling rule ... 12
enable email encryption with Smarsh. If you need assistance with this process please reference Support for Microsoft Exchange Server or contact Microsoft Support.
The instructions that follow are based upon Microsoft Exchange 2007 & 2010, both of which have a very similar architecture.
You will need the following information (which has been provided to you in an email):
Your fully qualified domain name (FQDN): obsmtp01.smarsh.com
Your journaling address space: yourdomain.journaltosmarsh.com
Navigate to the Send Connector configuration area
Sign into your Exchange 2007/10 server. Open your Exchange Management Console
1) From the areas on the left-hand side, select Hub Transport.
2) Select, from the tabs at the top, Send Connectors.
If you already have any existing Enabled Send Connectors, they may conflict with the ones that you are about to create.
Please ensure with your best judgment how to proceed with managing your current connectors, with these new ones.
**NOTICE**
You will need to choose the correct path to ensure proper routing of outbound emails and journaling.
If you have encryption only, will just be adding 1 Send Connector.
If you are setting up encryption, and already have a journaling rule in place, go to page 9, and follow the instructions from that point.
This will create a total of 2 Send Connectors, to ensure the journaled messages travel directly out through the internet. This prevents journaled messages
traveling through the outbound relay, along with regular messages.
Add a new Send Connector for using Encryption only
1) Enter a name for your Send Connector. (i.e. SmarshEncrypt)a. Leave Custom for “the intended use for the Send connector” b. Click Next >
3) Enter an asterisk (‘*’, as shown below) for the Address space. a. Enter a cost of 1
i Include all subdomain will automatically check itself, this is OK. b. Click OK
4) Review your newly created Address Space a. Click Next >
5) Select the bullet for Route mail through the following smart hosts: a. Click Add.
6) Select the bullet for: Fully qualified domain name (FQDN) a. Enter the following for that field
i. obsmtp01.smarsh.com b. Click OK
7) Ensure that obsmtp01.smarsh.com is correctly listed as the Smart host in the review screen. a. Click Next >
8) Choose None for “smart host authentication setting” a. Click Next >
9) Click Add, to add your Exchange mail server
11) Review your Configuration Summary a. If everything appears correct, click New
All of your outbound messages will now travel through Smarsh’s smart host.
Please review the email we have sent you regarding your encryption rules, and how to trigger the
service.
Add new Journaling Send Connector for Encryption with existing Journaling rule
12) Enter a name for your first Send Connector. (i.e. Smarsh Journaling)
a. Leave Custom for “the intended use for the Send connector” b. Click Next >
14) Enter the address space that we have provided to you via email. a. It should be the part of the journaling address after the ‘@’ symbol. b. Enter a cost of 1
c. Leave Include all subdomain unchecked d. Click OK
15) Review your newly created Address Space
a. Click Next >
16) At the next screen, choose Use domain name system (DNS) “MX records to route mail automatically.
18) Click Add, to add your Exchange mail server
19) Choose your Exchange mail server you will be applying this to
20) Review your Configuration Summary
Add new Encryption Send Connector for Encryption with existing Journaling rule
21) Enter a name for your Send Connector. (i.e. SmarshEncrypt)
a. Leave Custom for “the intended use for the Send connector” b. Click Next >
23) Enter an asterisk (‘*’ as shown below) for the Address space. a. Enter a cost of 2
i. Include all subdomain will automatically check itself, this is OK. b. Click OK
24) Review your newly created Address Space
25) Select the bullet for Route mail through the following smart hosts: a. Click Add.
26) Select the bullet for: Fully qualified domain name (FQDN)
a. Enter the following for that field i. obsmtp01.smarsh.com b. Click OK
27) Ensure that obsmtp01.smarsh.com is correctly listed as the Smart host in the review screen.
28) Choose None for “smart host authentication setting” a. Click Next >
29) Click Add, to add your Exchange mail server
a. If everything appears correct, click New
All of your outbound messages will now travel through Smarsh’s smart host.
All of your journaling messages will now travel directly to the internet.
Please review the email we have sent you regarding your encryption rules, and how to trigger the
service.
Verification of messages correctly traveling through Smarsh’s smart host
To test your configuration send a few test messages from your domain. Then email back on your
implementation case asking Smarsh to confirm.
If you currently have an SPF record setup for your domain. You will need to update this SPF record to the following: v=spf1 include:spf.smarsh.com –all
* The SPF record can be updated where your domain’s DNS is currently being hosted.