every Zimbra build
Zimbra-to-Zimbra migration software
Any version 8.8.15 or higher. Any OS. Any Zimbra edition. All easily migrated — with the source left intact.
When a Rolling Upgrade or a system-to-system rsync just won’t do, our bespoke migration software moves a complete Zimbra system (or selected domains) onto fresh infrastructure — recreating every account, user setting, and mailbox on the destination in staged passes that keep users live on the source until a short, final cutover — all while the original system stays fully intact as your fallback.
Built for the migrations that matter
- 01A Rolling Upgrade or an rsync migration isn’t appropriate — for example when S3 is present on the source system.
- 02You bought a Network Edition license and need to migrate off an existing Open Source system.
- 03You’re a Zimbra BSP partner onboarding a new customer’s to-be-retired self-hosted Zimbra system.
- 04You need as short a cutover window as possible — staged premigration passes move the mail while users stay on the source, so the cutover itself is minutes, not days.
- 05You’re a hosting provider absorbing customers in waves — domain-scoped licensing migrates one wave of domains at a time onto the same destination farm.
How it works — a two-path architecture
Provisioning recreates the full system — users, structure, and settings — while IMAPSYNC moves every message in parallel. The source is read, never altered, so you always have a clean rollback.
What migrates — the complete inventory
A whole Zimbra system… recreated — not approximated.
Developed over many months of continuous refinement across real customer migrations. Our software, working with IMAPSYNC, migrates a complete system – or selected domains – and leaves the source intact — just in case.
Infrastructure
- Classes of Service with the full inheritance chain preserved. A name that already exists is restored as <name>_restored rather than overwriting, and affected domains/accounts are repointed.
- Local domains & domain aliases, plus each domain’s default COS.
- Per-domain DKIM keys — signed mail keeps verifying at cutover with no DNS change.
- Distribution lists, their members, and DL aliases.
- Resource accounts (e.g. conference rooms).
- External / virtual accounts — off-domain users shared into internal folders or resources.
User accounts
- Password, display / given / surname
- Two-factor authentication — TOTP secret, scratch codes & app-specific passwords; users keep their authenticator, no re-enrollment
- Email aliases; preferred From address & display name
- Work title & company
- Full address, ZIP, and telephone
- Explicit per-account COS assignment
- All account-level ACEs and the zimbraId
- All Sieve scripts (filters)
- Personal Amavis block / allow lists & Trusted Senders
- Spell-check “words to ignore”
- Out-of-office auto-reply settings — message, external-sender variant, active window
- Mail forwarding — admin- and user-set forwarding addresses, with the local-delivery setting
- Account status (locked, closed, maintenance…) — applied after the final mail sync, so a disabled account can’t block its own migration
- Security-tightening CoS overrides — password locks, per-seat feature grants (EWS, S/MIME), quotas, session lifetimes; every one applied is logged for review
Mailbox content
- All address books — every contact folder and subfolder, not just /Contacts, each exported individually with names preserved.
- All calendars — every calendar folder and subfolder, not just /Calendar.
- Briefcase and Tasks.
- Email signatures.
- RSS / URL feed folders — recreated with their feed URLs, ready to poll.
- Folder shares — outgoing grants and incoming mountpoints, recreated in the correct dependency order. The complete share topology is preserved: shared calendar, contact, task, and briefcase folders are pre-created on the destination — even empty ones — so every grant lands.
- GALsync accounts.
- ActiveSync, S/MIME, ZCO/EWS, NE Backup — NE-only features skipped on a Network Edition → FOSS move; no FOSS equivalent, and they would fail account creation. Two-factor authentication is the exception — it migrates.
- Custom localconfig, MTA settings, SSL certs, branding, external auth (Okta / JumpCloud / AD) — these belong to the destination’s own build. Domains that authenticate against an external directory are detected and listed for you, so nothing is forgotten at cutover.
- Policy-loosening account overrides — one-off exemptions from Class-of-Service policy (e.g. a 2FA opt-out) are surfaced for review, not silently carried; the security-tightening direction migrates automatically.
- Domain-level ACEs — account-level ACEs do migrate.
- Admin-role flags (zimbraIsAdminAccount / delegated) — intentionally not set; admins are exported for reference and reconstructed deliberately.
- Per-domain public-service hostname / port / protocol — you set these on the destination, since they often change as a result of a migration.
Free & open-source: IMAP preflight, Broken Share Check & Remediation, License Count, and CoS Override Report scripts
Independent static code review of the migration software — in the same repo
