Security review
What access does SMTPReady need?
SMTPReady accepts mail only from local senders you allow and gets Microsoft permission to send from one configured mailbox. It does not need tenant-wide mail access, and Swobu infrastructure is not in the message path.
MAIL PATHYOUR NETWORK
→ MICROSOFTSwobu infrastructure is not in the mail-content path.
→ MICROSOFTSwobu infrastructure is not in the mail-content path.
01 · Local senderPrinter / scanner / app
Explicit source CIDR and sender policy. Unknown sources are rejected before queueing.
SMTP
02 · Customer Windows hostSMTPReady
Message is flushed, atomically stored and committed before SMTP 250.
HTTPS
03 · Customer tenantMicrosoft Graph
Customer-owned Entra identity and mailbox-scoped Exchange Application RBAC.
Access and data
Exactly what crosses each boundary.
Review the data, permission, proof, and revocation for each boundary.
- Mail content
- Customer host → Microsoft only.SMTPReady-operated infrastructure is not in the content path.
- Microsoft identity
- Customer-owned certificate.Private key stays in the Windows certificate store; configuration stores metadata/thumbprints.
- Mail authorization
- Exchange Application RBAC scoped to the relay mailbox.Provisioning rejects tenant-wide Entra mail app-role assignments.
- Scope proof
- Positive and negative test.Setup proves the relay mailbox is allowed and a distinct out-of-scope mailbox is denied.
- Accepted message
- Durably queued before
250.The queue is at-least-once: a crash after Microsoft accepts a message can create a duplicate rather than silent loss. - Operational logs
- No bodies, attachments, SMTP passwords, OAuth tokens or private keys.Support bundles exclude the same secret/content classes.
- Device access
- Explicit local source rules.Domain/Private firewall profiles and sender policy constrain ingress.
- License service
- Separate from mail security.License validation does not grant Microsoft mail authority.
Verify the scope
Test what must fail, not only what works.
relay mailbox202 · allowed
unrelated mailbox403 · denied
If the unrelated mailbox is ever accepted, treat it as a security failure: stop the service and repair the Microsoft scope before resuming delivery.
Revoke access
Stop delivery, revoke Microsoft access, or remove local state.
- Stop delivery nowStop the Windows service.
- Revoke Microsoft permissionRevoke the scoped Exchange/Entra assignment or credential.
- Delete local stateUse the explicit purge uninstall only when you intend irreversible data removal.