Built to pass your IT review
Secure Mail Merge for Outlook
Personalized emails sent from your own mailbox. No cloud upload, no data sharing, and only two things to review: the add-in and the permissions it asks for.
Works in the new Outlook, classic Outlook, Mac, and the web. No Word required.
★★★★★ 4.9 stars from 67 reviews on Microsoft AppSourceRead the full IT security documentation
“The Outlook integration and ability to attach docs make this tool invaluable for our daily activity.”
Where your campaign data goes: nowhere
Most mail merge tools ask you to upload your recipients to their cloud so their servers can send on your behalf. SecureMailMerge is built the other way round: the merge happens on your computer and the mail leaves from your mailbox.
- Processing happens inside Outlook
- The add-in reads your spreadsheet and assembles every message locally, in the Outlook add-in sandbox on your own machine. Sending goes through your own mailbox via Microsoft Graph, the same interface Outlook itself uses. Nothing is routed through us.
- Nothing is uploaded to us
- Your recipients, spreadsheets, attachments, and email content are never sent to us or to a third party. This is not a retention policy we could change: we operate no server that receives campaign data.
- Your Microsoft 365 token stays between you and Microsoft
- The access token that lets the add-in send on your behalf is stored on your computer and exchanged only with Microsoft. It is never transmitted to our servers.
- Distributed and sandboxed by Microsoft
- SecureMailMerge is published on Microsoft AppSource, carries a Microsoft Publisher Attestation, and runs in the standard Outlook add-in sandbox. Installation is the same review and approval flow as any other Microsoft 365 add-in.
The two architectures, compared
Typical mail merge service
- Your recipients and spreadsheet
- Their cloud servers
- Your recipients receive mail from their infrastructure
Your data is copied out of your tenant. Their retention, their access controls, their breach surface.
SecureMailMerge
- Your recipients and spreadsheet
- Your Outlook, on your computer
- Your recipients receive mail from your mailbox
Your data never leaves the path it is already on. Your retention, your access controls, your audit trail.
The one server we do run
A licensing server checks whether your own email address holds a commercial license, and stores that email address for as long as the license is active and, for purchasers who arrived from one of our United States advertisements, the pseudonymous advertising click identifier described further down this page, for up to 100 days. It performs no mail merge work and never receives campaign data. It runs on European servers in Microsoft Azure. We publish the minimal firewall rules it needs so you can restrict everything else.
What we cannot see
This is a matter of capability, not policy. There is no endpoint these things could be sent to, so collecting them is not a feature we could switch on later.
- Your recipients and their email addresses
- Your spreadsheets and the data in their columns
- The content of your emails
- Your attachments
- Who you sent to, and when
What we do see, so you can plan around it
The add-in reports anonymous usage counts (how often it runs, how many emails were sent) through Fathom Analytics, and technical error diagnostics through Sentry. Neither identifies you, your organization, or your recipients. Both are documented in our privacy policy, and the firewall rules we publish let you block them outright.
Designed for GDPR compliance
We are not going to wave a certification badge at you. No badge proves that your recipient data stayed inside your tenant. What we can show you is where the data sits and the paperwork that covers it.
- Your compliance posture keeps applying
- Because recipient data and message content stay inside your Microsoft 365 tenant, the controls you already run keep working: retention policies, DLP rules, eDiscovery, journaling, and audit logs all see these emails exactly as they see any other mail from that mailbox.
- An EU company, under EU law
- SecureMailMerge is built by Sol Inventum OÜ, a private limited company registered in Tallinn, Estonia. The licensing server sits in European Microsoft Azure data centers.
- A signed DPA is available
- We publish a Data Processing Addendum covering the limited processing we do perform, so your DPO has something concrete to file.
- Minimal permissions, documented
- We list every Microsoft 365 permission the add-in requests and why it needs it, plus the firewall requirements, so an admin can review the exact scope before approving anything.
The same standard applies to this website
There are no tracking pixels and no third-party advertising tags on this page. Analytics come from Fathom Analytics in strict EU isolation mode, which is cookie-free. We measure our own advertising without pixels: a visitor recognized as being in the United States who arrives from an advertisement gets a signed first-party cookie holding a pseudonymous click identifier, the time it was captured, and a signature. No name, no contact details. Everyone else receives only technically required cookies, and all of it is written down in our privacy policy.
How it works in practice
Four steps, none of which involve creating an account with us.
- 1
Install from Microsoft AppSource
Install it yourself, or have your admin deploy it centrally to selected users through the Microsoft 365 admin center.
- 2
Open it in Outlook
Start a new email and open the add-in from the ribbon. It runs inside Outlook on Windows, Mac, the new Outlook, and the web.
- 3
Merge from your spreadsheet
Point it at an Excel or CSV file with a "To" column and any columns you want to personalize. The file is read on your computer and never uploaded.
- 4
It sends from your own inbox
Preview the messages, then send. Each one goes out through your own mailbox, lands in your Sent Items, and looks to the recipient exactly like an email you wrote by hand.
Questions IT and security teams ask us
- Does my recipient data leave my computer?
- No. The spreadsheet is read and the emails are assembled inside Outlook on your own machine. The finished messages go to Microsoft Graph, the same interface Outlook uses to send any email, and then to your recipients. Your recipient data is never transmitted to SecureMailMerge or to any third party, and you can confirm that in the add-in network traffic: the only request that reaches us is the license check.
- Do you store my emails or attachments?
- No, and there is nothing to store. We operate no server that receives email content, attachments, or spreadsheets. The one server we do run checks whether your own email address holds a commercial license. It performs no mail merge work, and that request carries only your email address, a product name, and a timestamp.
- Is SecureMailMerge GDPR compliant?
- Designed for it, not certified against it. We hold no certification seal. In practice: your recipient data and message content stay inside your own Microsoft 365 tenant, so your existing retention, DLP, and audit controls keep applying. Sol Inventum OÜ is an EU company registered in Estonia, and we provide a signed Data Processing Addendum for the limited processing we do perform.
- What does my IT admin need to approve?
- Two things: the add-in, and the permissions it requests. Install it from AppSource, or deploy it centrally from the Microsoft 365 admin center. Each permission is granular and documented with its reason on the permissions page: sign-in and profile, contacts, calendar read, mail read and write, mailbox settings, and a refresh token. Your spreadsheet needs no Microsoft permission at all, because it is read locally. For firewall rules there is one host to allow beyond your existing Microsoft 365 endpoints: https://www.securemailmerge.com, with GET to load the add-in and POST to the license endpoint.
- Does it work with shared mailboxes, Windows, Mac, and the web?
- All four Outlook versions, yes. It runs in classic Outlook on Windows, the new Outlook, Outlook for Mac, and Outlook on the web. Shared mailboxes work in the send-as direction: create the email in your own mailbox, change the "From" address to the shared mailbox, then run the campaign as normal, if your tenant already lets you send from that address. Recipients see the shared mailbox and replies go back to it, though the sent copy lands in your own Sent Items. Opening the add-in inside a shared mailbox is not supported, because Outlook does not allow it.
- How is this different from Word mail merge?
- Word cannot do three things this does. It cannot attach a different file per recipient, cannot send from the new Outlook or Outlook on the web at all, and gives you no preview of the finished messages. SecureMailMerge runs natively in every Outlook version, supports per-recipient attachments, cc and bcc, fallback values, and scheduling, and keeps the same local-only data path.
- How is this different from a newsletter or campaign tool?
- Newsletter platforms upload your recipients to their cloud and send from their own infrastructure, which puts your recipient data under their retention and access controls and sends from their sending domain. SecureMailMerge sends one-to-one mail from your mailbox, so replies come back to you normally and the message looks like ordinary correspondence rather than a bulk campaign.
Approve the add-in, or try it yourself first
The free version is fully functional for non-commercial use and adds a small promotional footer. Nothing to sign up for, and no data to hand over.
Get started today
Install it, run one merge from your own mailbox, and show your IT team exactly where the data went: nowhere.
Get it free for Outlook