#Requirements
Check this list before you start. Everything here is needed either on day one or when you enable a particular delivery channel.
#Microsoft side
| Requirement | Why |
|---|---|
| A Microsoft Entra ID tenant (included with Microsoft 365) | Sign-in to the portal and the source of user and group data. (Google Workspace customers need a Workspace domain instead; see Google Workspace.) |
| An account that can register applications and grant admin consent (Application Administrator or Global Administrator) | Needed once, to create the SignetMail app registration and approve its permissions. |
| Microsoft 365 / Exchange Online mailboxes | For the Outlook add-in channel and the optional transport rule. |
| Permission to deploy add-ins in the Microsoft 365 admin center | To roll out the Outlook add-in to users. |
For on-premises Active Directory, synchronise identities to Entra ID with Microsoft Entra Connect; SignetMail reads the synchronised attributes.
#Server side
| Requirement | Details |
|---|---|
| A Linux server reachable from the internet | The reference setup uses a small VPS (2 vCPU, 4 GB RAM is plenty) running Rocky Linux 10. Any Linux that runs Docker works. |
| Docker Engine with the Compose plugin | The application is shipped as a container image. |
| A public DNS name | For example app.example.com, with an A record (and optionally AAAA) pointing at the server. |
| Ports 80 and 443 open to the internet | 80 is used for the Let's Encrypt challenge and redirects; 443 serves everything. |
| Port 22 (SSH) restricted to your own IP | For administration only. |
| Access to the container image | The image ghcr.io/aljazeferl/signetmail-api is private; you need a GitHub token with read:packages once, to pull it. |
#Client side
| Channel | Requirement |
|---|---|
| Outlook add-in | New Outlook for Windows, Outlook on the web, or Outlook for Mac, signed in with a work account. Classic Outlook for Windows uses the agent instead. |
| Windows agent | Windows PCs joined to an Active Directory domain, running classic Outlook; the API must be reachable with Kerberos (see Kerberos on the server side). |
| Transport rule | Exchange Online PowerShell access to create a mail-flow rule. |
#Browsers for the portal
Current versions of Edge, Chrome, Firefox or Safari. The portal is available in English and Slovenian (language switcher in the sidebar).
#Sizing and limits
- A single small server comfortably handles thousands of mailboxes: the work per request is a template render of a few kilobytes.
- Requests are rate-limited (600 per minute per IP, 120 per minute for public paths) and request bodies are capped at 2 MB; uploaded logos are limited to 1 MB.
- The directory is held in memory. Very large tenants (hundreds of thousands of users) should plan for proportionally more RAM.