Exchange mail flow guides › Inbound: POP3 and IMAP retrieval into Exchange

Where to install a POP3/IMAP connector: on the Exchange server, a member server, or a workstation

A POP3/IMAP connector needs two things from the network: outbound access to the provider’s POP3 or IMAP ports, and SMTP access to one receive connector of your Exchange Server. Nothing has to reach it from the internet. That is why it can run on the Exchange server itself, on any other Windows Server, or on a Windows 10/11 machine — POPcon is a Windows service and its requirements list Windows Server 2012 to 2025 and Windows 7 to 11. The placement decides which receive connector and which remote IP range you configure, which firewall the SMTP session on port 25 has to pass, and which antivirus exclusions you need. This guide sets the three placements side by side and lists the checks for the one symptom that placement causes: the connector downloads mail fine but cannot reach Exchange.

Updated on 2026-09-30

What the connector needs, wherever it runs

The requirements are the same at every placement; only the way to meet them differs. The figures come from the POPcon system requirements, the POP3/IMAP settings, the Exchange settings and the knowledge base.

NeedDetailWhere it is set
Windows to run the serviceWindows Server 2025, 2022, 2019, 2016, 2012 (incl. R2), Windows SBS 2011, or Windows 11, 10, 8, 7 (x86 or x64); no special CPU or memory requirementsYour choice of machine
Outbound to the providerPOP3 on port 110 or 995 (TLS), IMAP on port 143 or 993 (TLS), or the port your provider names; the connection is always opened by the connectorPer account in POPcon; any firewall or proxy between the machine and the internet
SMTP to ExchangeThe Exchange server’s hostname or IP address (the help page gives exchange.local or 127.0.0.1 as examples) and the SMTP port, 25 by defaultPOPcon, Exchange Server settings; the receive connector on the Exchange side
Disk space10 MB for the program plus the space to store downloaded messages temporarily until Exchange has accepted themThe POPcon program folder on the machine
Network adaptersOne adapter is sufficient; with two or more, POPcon lets you pick the adapter for external connections (to the provider) and the one for internal connections (to Exchange)POPcon, Advanced options → Network configuration
AdministrationPOPcon Administrator runs on the same machine or on any other machine on the network with access to the service, over TCP ports 22772–22774Windows firewall on the machine that runs the service

The three placements

On the Exchange side, what matters is the receive connector. Microsoft describes the default receive connector Default Frontend <ServerName> on Exchange 2016, 2019 and SE as the one that “accepts anonymous connections from external SMTP servers” and calls it “the common messaging entry point into your Exchange organization”; it listens on port 25 on all available addresses and its remote IP ranges cover all IPv4 and IPv6 addresses (Receive connectors in Exchange Server). The same page defines the remote network settings of a receive connector as “the source IP addresses that the Receive connector listens to for connections”. So as long as nobody has narrowed those ranges, a connector on any machine in the network is inside them, and the one setting the Exchange 2013/2016 configuration guide adds is the Anonymous users permission group on that connector. The differences between the placements are elsewhere.

On the Exchange serverOn another Windows Server (member server)On a Windows 10/11 workstation
Exchange server address in POPconThe server’s own name or 127.0.0.1The Exchange server’s network name, not the internet domain nameSame as member server
Path of the SMTP session on port 25Stays on the machine; no firewall in betweenWindows firewall on the Exchange server and any network firewall between the two machines must allow port 25 from this machineSame as member server; workstations are more often in a network segment that a firewall separates from the servers
Receive connectorDefault Frontend on port 25 with Anonymous users enabled; if its remote IP ranges have been narrowed, the address of the machine the connector runs on must be in them (all three placements)
Antivirus exclusionsThe POPcon program folder from real-time scanning, plus Microsoft’s exclusion list for Exchange servers (see below)The POPcon program folder from real-time scanningSame as member server; endpoint security products on workstations may also intercept outbound SMTP
Availability of retrievalAs long as Exchange runs, the connector runsAs long as the server runs; Exchange can be restarted without stopping retrieval, the downloaded messages wait as files until Exchange accepts themOnly while the PC is on; mail waits at the provider in the meantime
POPcon AdministratorLocally, or from another machine over ports 22772–22774SameSame
Proxy on the way to the internetIf outbound traffic leaves through a proxy, POPcon takes the proxy address and port for its POP3 and IMAP connections; a Microsoft ISA Server needs two outbound packet filters, remote port 110 (or 995) for POP3 and remote port 25 for SMTP (all three placements)

The middle column is the usual choice when the Exchange server is not supposed to carry anything but Exchange: the connector then behaves like any other application server that submits mail, and the Exchange side needs nothing beyond the anonymous permission on the receive connector. The left column is the simplest to set up because the SMTP session never leaves the machine; its price is that the Exchange server now also holds the antivirus and file-handling questions of the connector. The right column works, and the requirements say so, but the retrieval schedule then depends on a PC being on.

Antivirus on the machine that runs the connector

POPcon stores every downloaded message as a file in its program folder while it is being delivered to Exchange, and messages that Exchange rejects go to the TOOLARGE or BADMAIL subfolders, from where they can be moved to PICKUP for another attempt (how to resend them). A real-time virus scanner that deletes or quarantines such a file while POPcon works on it interferes with that; the knowledge base article POPcon hangs when my virus scanner deletes infected .msg files therefore recommends excluding the POPcon program folder (typically C:\Program Files (x86)\POPcon) from real-time scanning and scheduling a periodic scan instead. Since version 2.8, POPcon sends a postmaster notification when a message file disappears unexpectedly rather than hanging.

On the Exchange server itself the same class of problem exists for Exchange’s own files, and Microsoft has a page for it: Running Windows antivirus software on Exchange servers (applies to 2016, 2019 and SE). Its warning: “The biggest potential problem is that a program (such as antivirus) might lock or quarantine an open log or database file that Exchange needs to modify. This can cause severe Exchange Server issues, including potential data loss.” The page lists the folders, processes and file-name extensions to exclude from file-level and memory-resident scanning and notes that remote scanning can contribute to the same file locks. If you place the connector on the Exchange server, the POPcon folder is one more entry on a list you should already be maintaining.

Two more notes on the same theme. Some endpoint security products intercept or block outbound SMTP; the knowledge base suggests disabling them temporarily to test when delivery to Exchange fails. And on POPcon PRO, whose antivirus engine scans the downloaded messages, Windows Data Execution Prevention can interfere with that engine; the fix in Windows Data Execution Prevention (DEP) is crashing the POPcon antivirus engine is to set DEP to “Turn on DEP for essential Windows programs and services only” on the machine that runs POPcon.

“Downloads fine but cannot reach Exchange”: the checks

This is the symptom that placement causes, and it appears almost only when the connector runs on a different machine than Exchange. The knowledge base article POPcon downloads email fine but cannot reach my Exchange server lists the checks in this order:

  1. The Exchange server address. Use the server’s network name (for example exchangeserver), not the internet domain name of your mail. The POPcon log file shows the IP address POPcon is actually trying to reach; verify it is the Exchange server’s.
  2. The Exchange services. The Microsoft Exchange Transport service must be started on the Exchange server.
  3. Network connectivity. ping exchangeserver from the POPcon machine.
  4. SMTP port 25. telnet exchangeserver 25 from the POPcon machine must show the Exchange SMTP banner (a line starting with 220). If it does not, port 25 is blocked.
  5. Firewalls. The Windows firewall on the Exchange server and any network firewall between the two machines must allow port 25 from the POPcon machine.
  6. Endpoint security. Some antivirus or antispam products intercept outbound SMTP; disable them temporarily to test.
  7. The receive connector. Verify that the POPcon machine’s IP address is within the allowed remote IP ranges of the receive connector (its Network tab).

When the log shows “Could not reach Exchange SMTP server — check that IP port 25 is not blocked”, the article with that title gives the shorter version of the same list. What Exchange answers once the connection works, and what each reply means, is in Exchange SMTP error codes explained; the full setup from accepted domain to first test is in How to download POP3 and IMAP mailboxes into Exchange 2016, 2019 and SE.

Moving the connector to another machine

The placement is not a decision for life. To move POPcon 4.x to another machine, install it there, stop the POPcon service, copy popcon.config and all UIDS_*.dat files from the old program folder into the new one, and start the service (How can I transfer my POPcon configuration settings to a new server?). The UIDS files are the lists of messages already downloaded from each mailbox; without them a mailbox set to “leave messages on the server” would be downloaded again. Alternatively, POPcon Administrator has File → Export Config and File → Import Config for the account settings. After the move, check the one Exchange-side setting the placement touches: if the receive connector’s remote IP ranges were narrowed to the old machine, they have to include the new one.

If the standard installer cannot run on the target machine because of permission restrictions or Group Policy, the knowledge base describes an alternative installation method: install on a temporary machine, copy the program folder, run POPconSrv.exe there and choose Install and start service from its maintenance menu.

Frequently asked questions

Does the connector have to run on the Exchange server itself?

No. POPcon runs as a Windows service on Windows Server 2012 to 2025 or on Windows 7 to 11, on the Exchange server or on any other Windows machine in the network. What changes with the placement is the path the SMTP delivery takes: from another machine the connector must reach Exchange on TCP port 25, and the receive connector that answers there must accept connections from that machine's address.

Can I run it on a Windows 10 or Windows 11 PC?

Yes. The POPcon requirements list Windows 11 and Windows 10 (x86 and x64) beside the server editions. The service runs for as long as the PC runs, so a PC that is switched off in the evening collects mail only during the day; the messages wait in the provider mailboxes in the meantime. For round-the-clock retrieval a server or an always-on machine is the better place.

Which receive connector does the connector talk to?

The one that listens on port 25 for anonymous SMTP connections. On Exchange 2016, 2019 and SE that is the receive connector "Default Frontend <ServerName>", which Microsoft describes as accepting anonymous connections from external SMTP servers on port 25 from all IPv4 and IPv6 addresses. The Exchange configuration guide enables the "Anonymous users" permission group on it. If somebody has narrowed its remote IP ranges, the address of the machine the connector runs on has to be added; the knowledge base article on "Could not reach Exchange SMTP server" starts with exactly that check.

Do I have to exclude anything from antivirus scanning?

Exclude the POPcon program folder from real-time scanning wherever the connector runs: POPcon writes every downloaded message as a file and reads it back for delivery, and a real-time scanner that removes such a file interferes with that. Schedule a periodic scan of the folder instead. On the Exchange server itself Microsoft additionally lists the Exchange folders, processes and file types that a Windows antivirus program must not scan, because a locked or quarantined log or database file can cause severe problems including data loss.

Can I administer the connector from my own desk?

Yes. POPcon Administrator is a separate program that can run on any machine on the network with access to the POPcon service; it talks to the service over TCP ports 22772 to 22774 (the German knowledge base article also lists 22775). Open those ports in the Windows firewall of the machine that runs the service, and between the two machines if a firewall sits there. Closing the administrator does not stop the service.

More in the Exchange mail flow guides, on the POPcon product page, the download page or in the knowledge base. Auf Deutsch: Wo installiert man einen POP3-/IMAP-Connector: auf dem Exchange-Server, einem Mitgliedsserver oder einem Arbeitsplatz-PC?