Microsoft Exchange New Mail Notification (NEWMAIL)

Microsoft Exchange e-mail servers use a protocol that Wireshark refers to as "NEWMAIL" to notify clients (such as Microsoft Outlook) that their mailbox has received a new e-mail message. The port is dynamically chosen by the client when logging in to the e-mail server and is transmitted in a MAPI Register Push Notification (mapi.opnum == 4) packet.

Protocol dependencies

Example traffic




The NEWMAIL dissector is partially functional. The notification payload in the packets is displayed, but there is no public documentation that explains what the data stands for.

Example capture file

