Quantcast
Channel: Exchange Server 2013 - Mail Flow and Secure Messaging forum
Viewing all 3660 articles
Browse latest View live

Authoritative domain unknown address error 550 'no such user here' for other addresses

$
0
0

I was administering an Exchange server for multiple email domains that was previously receiving forwards from various internet email hosts until the site had reliable internet with a static IP, updated the internet MX record, etc. Once that happened, we reconfigured the 'accepted domains' from 'External Relay' to Authoritative.

Unfortunately now all email is rejected when it's addressed to email addresses that are not that user's primary address:

5.1.0 - Unknown address error 550-'No Such User Here"'

So let's say I have employee John Smith with the following email addresses:

  • john.smith@domain.com
  • johns@domain.com
  • smith.john@domain.com

With the previous configuration, John Smith would receive emails that match any of those three addresses. Since flipping over to Authoritative, he's only receiving the bolded primary address!

Any and all insight would be appreciated!


Exchange 2007 -2013 Mail Flow Problem

$
0
0

hello guys,

i have problem with exchange 2013 - 2007 mailflow.

recently i added exchange 2013 to our exchange organization everything seems to work fine , well at least for 2 days now exchange 2013 users cant send email to exchange 2007 users and exchnage 07 cant send to exchange 13.

all messages are stuck in queue of both servers.

  • i think it's a kerberos problem i activated kerberos logging and there are a lot of kerberos errors. (event id 3 )
  • exchange and legacy exchange is enabled on default receive connectors
  • exchange 2013 have SmtpReceive warnong with event id 1035 (Inbound Authentication failed with error Target Unknown for Receive connector DefaultFrontend ex13.ex.local. .......authentication mechanism is ExchangeAuth.
  • exchange 2013 have SmtpSend Error with Event ID 2017on exchange 2013 i get Core Event ID 3005 (Rpc Htto) Making Client Access 2010 Server .... (i dont have any 2010 server - OA is Disabled on 2007 Servers)
  • i checked SPN for both server names are correct but i have multiple duplicate spn's for 2007 server (ex07 - ex07.ex.local)
  • Smtp log for send and receive attached to this post

any help would be appreciated

thanks!

Problem with linked mailbox

$
0
0

Situation: Domain:A and Domain:B

Server 1: Win2012 + Exchange2013 + Domain A

Server 2: Win2012R2 + Domain B

user victor@domainA has mailbox now the same uservictor@domainB wonts to use in one logon the both.

so he wants to choise from wich account he sends email.

I tried to make a linked mailbox but I got this error: The value "victor@prinfotech.com" of property "UserPrincipalName" is used by another recipient object "". Please specify a unique value.

What went wrong.

Email is not deliveried to mailbox

$
0
0

Hi all,
In my Exchange 2013 system there is one user that cannot receive any email although messages come to Exchange queue, here example log

As you can see, I sent her a message from my gmail , Exchange received my message but cannot delivery to user's mailbox, I cannot find it in Toolbox >> QueueViewer and I don't know where it is ...
Please give me some advice to fix this issue, thank you very much

Address Rewriting doesn't appear to work?

$
0
0

Afternoon,

following the examples from https://technet.microsoft.com/en-us/library/aa997185%28v=exchg.150%29.aspx?f=255&MSPPError=-2147217396 it should be really easy to get the edge server to rewrite the domain on its way out but I can't seem to get it working.

New-AddressRewriteEntry -Name "Domain Change" -InternalAddress mydomain.co.uk -ExternalAddress newdomain.co.uk -OutboundOnly $true

I was hoping this would rewrite my email mike@mydomain.co.uk and change it through the edge server by this policy to mike@newdomain.co.uk

I have tried single recipients as well but can't get it to apply this rule.

The Transport Agent is running and confirmed by using Enable-TransportAgent "Address Rewriting Outbound Agent"


.: Lister :.

Reduce Spoofed Messages

$
0
0

We are in a Office365-Exchange 2013 Hybrid environment today, slowing migrating users to the cloud.

We seem to receive a lot of spoofed emails and was looking for some tips/tricks to get a better hold of this. Usually these are emails that are sent to internal folks from senior publicly noticed figures such as the CEO, CFO etc.

The emails look legit, even have the correct alias@contoso.com addresses displayed unless you actually dig into the headers to see different. 

All our email is scanned by Microsoft EOP as they are our MX record holders then passed thru to our On-Premises mail users. 

Is it possible to tighten security by setting the on-premises and MSOL servers to never accept or block email sent from the outside when being sent from alias1@contoso.comto alias2@contoso.com?

Thanks in advance.

On premisis-Send connector-30 minute mas send limit

$
0
0

Hey there,

We have our Exchange environment configured to deliver all mail through a send connector that authenticates with our ISP's reputable mail server for mail delivery, in order to avoid having to deal with trust and blacklisting ourselves directly.  We discovered the other day, that while we have an agreement with them to not cap our daily message sending (where their average user is), we are still subject to a 200 message/30min limit, after which subsequent message are rejected/bounced with the below error:

Remote Server returned '550 User has exceeded outgoing limit G_SPAM_USER_MAX or send_limit(200)

and if our server continues to try to send mail, we eventually start getting:

451 4.4.0 SMTPSEND.SuspicousRemoteServerError; remote server disconnected abruptly; retry will be delayed

I started looking at send connector configuration options, as well as Message throttlinghttps://technet.microsoft.com/en-us/library/bb232205(v=exchg.150).aspx

but I'm not sure the best way (if there is any) to accommodate for this.  I was hoping for configuration options that would allow me to setup the existing send connector to work around this limitation by queuing, either before the limit is reached, or after by reacting differently to the 550 send limit response, but so far I'm not seeing anything like that.

I get the feeling from the Message Throttling article that I should be looking at this more from a per-user standpoint, and throttling message sending for each user, which would likely resolve the issue as the limit is only an issue of someone tries to send an excessive mass email, but I'm not sure.

Can anybody give me a swift kick in the right direction on this?  Or maybe a couple different directions if there are options on how to address this? Thanks!

Mail stuck in queue on 2013

$
0
0

Hi, I am working my way through a migration project and I feel like i am very close to being able to bring my W2012/Ex2013 server into production.  I have moved a couple mailboxes over to the new server running W12/E13 and they can send out email, but email will not make it to the mailboxes.  I have a hosted spam filter (barracuda) where I can see email for recipient, the email has been delivered to the correct mail server, but has not made it to the mailbox.  I still have the W2008/Ex2010 server in production and most mailboxes are there.  Any ideas on what might be causing the mail to get hung in the queue.  I can see it in the queue.

Sally


Inbound Email Delayed from Edge Server to Internal CAS-MBX Server; No errors or delay messages

$
0
0

Email from the internet is delayed between 0-10 minutes. I can see the message come in on the Edge server in ProtocolLogs-->SmtpReceive. I can see it depart the Edge server (for the internal server) in ProtocolLogs-->SmtpSend... but sometimes there is a delay between the Recieve and Send logs. And I see no reason why.

Both servers are Exchange 2013 CU11 on Win2k12R2.  CPU is sitting at like 1% and memory at 1.9GB/6.0GB used.

Sometimes the mail is instant, others it is delayed a few minutes. Nothing bad.  I never hear of anyone getting an automated "Your mail is delayed" message.  But in this world of everything instant, they're asking for instant email.

Org is very small, like 10 people.  Internal server is a single multi-role server. No DAG.

I see no errors in the Event Viewer and I never catch anything in a queue (Get-Queue).

Microsoft Filtering Management Service service can't start with error 0x80004005: Unspecified error

$
0
0

Hi Microsoft and experts in the form,

My two Exchange 2013 CU8 server Exchange transport service failed to start due to the dependency Microsoft Filtering Management Service stopped. The error message is listed below. I have tried all resolutions in the post but issue not fixed.

Log Name:      System
Source:        Service Control Manager
Date:          1/27/2016 5:25:14 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Exch02.testoml.com
Description:
The Microsoft Filtering Management Service service terminated with the following error:
Unspecified error

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          1/27/2016 11:53:40 AM
Event ID:      10001
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Exch02.testoml.com
Description:
Unable to start a DCOM Server: {2DC947D7-A2DC-4276-A554-891346CE2032} as NT AUTHORITY/NetworkService. The error:
"5"
Happened while starting this command:
"D:\Exchange2013\FIP-FS\Bin\FSCConfigurationServer.exe" -Embedding

For Filtering Management Service failed due to dcom error 10001. I already tried to give the full permission to on CLSID.

Any suggestions would be highly appreciated.


Best regards,

Robert Li
Partner Online Technical Community
-----------------------------------------------------------------------------------------
We hope you get value from our new forums platform! Tell us what you think:
http://social.microsoft.com/Forums/en-US/partnerfdbk/threads
------------------------------------------------------------------------------------------
This posting is provided "AS IS" with no warranties, and confers no rights.

Can't receive/Delayed pdf attachments of more than 100kb from a few different contacts

$
0
0

I have two customers who can't send me pdf attachments larger than 100kb without them failing or being delayed up to 24hours. Everyone else can send the same or larger attachments through just fine.

Things I have tried to fix the problem :

Disable spam filtering

Disable tarpitting

increase timeout to 2:30:00

Verify MTU is set correctly

Whitelist the IP Address of the sender

Some logs of a file that didn't go through:

 

2016-01-25T21:37:47.387Z,EXCHANGE01\Default EXCHANGE01,address,0,10.0.1.19:25,x.x.x.x:60062,+,,

2016-01-25T21:37:47.387Z,EXCHANGE01\Default EXCHANGE01,address,1,10.0.1.19:25,x.x.x.x:60062,*,SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders,Set Session Permissions

2016-01-25T21:37:47.402Z,EXCHANGE01\Default EXCHANGE01,address,2,10.0.1.19:25,x.x.x.x:60062,>,"220 exchange01.domain.local Microsoft ESMTP MAIL Service ready at Mon, 25 Jan 2016 15:37:46 -0600",

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,3,10.0.1.19:25,x.x.x.x:60062,<,EHLO Zixserver,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,4,10.0.1.19:25,x.x.x.x:60062,>,250-exchange01.domain.local Hello [x.x.x.x],

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,5,10.0.1.19:25,x.x.x.x:60062,>,250-SIZE,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,6,10.0.1.19:25,x.x.x.x:60062,>,250-PIPELINING,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,7,10.0.1.19:25,x.x.x.x:60062,>,250-DSN,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,8,10.0.1.19:25,x.x.x.x:60062,>,250-ENHANCEDSTATUSCODES,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,9,10.0.1.19:25,x.x.x.x:60062,>,250-STARTTLS,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,10,10.0.1.19:25,x.x.x.x:60062,>,250-X-ANONYMOUSTLS,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,11,10.0.1.19:25,x.x.x.x:60062,>,250-AUTH NTLM,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,12,10.0.1.19:25,x.x.x.x:60062,>,250-X-EXPS GSSAPI NTLM,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,13,10.0.1.19:25,x.x.x.x:60062,>,250-8BITMIME,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,14,10.0.1.19:25,x.x.x.x:60062,>,250-BINARYMIME,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,15,10.0.1.19:25,x.x.x.x:60062,>,250-CHUNKING,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,16,10.0.1.19:25,x.x.x.x:60062,>,250-XEXCH50,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,17,10.0.1.19:25,x.x.x.x:60062,>,250-XRDST,

2016-01-25T21:37:47.434Z,EXCHANGE01\Default EXCHANGE01,address,18,10.0.1.19:25,x.x.x.x:60062,>,250 XSHADOW,

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,19,10.0.1.19:25,x.x.x.x:60062,<,STARTTLS,

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,20,10.0.1.19:25,x.x.x.x:60062,>,220 2.0.0 SMTP server ready,

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,21,10.0.1.19:25,x.x.x.x:60062,*,,Sending certificate

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,22,10.0.1.19:25,x.x.x.x:60062,*,CN=exchange01,Certificate subject

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,23,10.0.1.19:25,x.x.x.x:60062,*,CN=exchange01,Certificate issuer name

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,24,10.0.1.19:25,x.x.x.x:60062,*,****,Certificate serial number

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,25,10.0.1.19:25,x.x.x.x:60062,*,****,Certificate thumbprint

2016-01-25T21:37:47.465Z,EXCHANGE01\Default EXCHANGE01,address,26,10.0.1.19:25,x.x.x.x:60062,*,exchange01;exchange01.domain.local,Certificate alternate names

2016-01-25T21:37:47.543Z,EXCHANGE01\Default EXCHANGE01,address,27,10.0.1.19:25,x.x.x.x:60062,*,,"TLS protocol SP_PROT_TLS1_0_SERVER negotiation succeeded using bulk encryption algorithm CALG_AES_128 with strength 128 bits, MAC hash algorithm CALG_SHA1 with strength 160 bits and key exchange algorithm CALG_RSA_KEYX with strength 2048 bits"

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,28,10.0.1.19:25,x.x.x.x:60062,<,EHLO server,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,29,10.0.1.19:25,x.x.x.x:60062,*,,TlsDomainCapabilities='None'; Status='NoRemoteCertificate'

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,30,10.0.1.19:25,x.x.x.x:60062,>,250-exchange01.domain.local Hello [x.x.x.x],

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,31,10.0.1.19:25,x.x.x.x:60062,>,250-SIZE,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,32,10.0.1.19:25,x.x.x.x:60062,>,250-PIPELINING,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,33,10.0.1.19:25,x.x.x.x:60062,>,250-DSN,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,34,10.0.1.19:25,x.x.x.x:60062,>,250-ENHANCEDSTATUSCODES,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,35,10.0.1.19:25,x.x.x.x:60062,>,250-AUTH NTLM LOGIN,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,36,10.0.1.19:25,x.x.x.x:60062,>,250-X-EXPS GSSAPI NTLM,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,37,10.0.1.19:25,x.x.x.x:60062,>,250-8BITMIME,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,38,10.0.1.19:25,x.x.x.x:60062,>,250-BINARYMIME,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,39,10.0.1.19:25,x.x.x.x:60062,>,250-CHUNKING,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,40,10.0.1.19:25,x.x.x.x:60062,>,250-XEXCH50,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,41,10.0.1.19:25,x.x.x.x:60062,>,250-XRDST,

2016-01-25T21:37:47.574Z,EXCHANGE01\Default EXCHANGE01,address,42,10.0.1.19:25,x.x.x.x:60062,>,250 XSHADOW,

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,43,10.0.1.19:25,x.x.x.x:60062,<,MAIL FROM:<****> SIZE=278779,

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,44,10.0.1.19:25,x.x.x.x:60062,*,address;2016-01-25T21:37:47.387Z;1,receiving message

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,45,10.0.1.19:25,x.x.x.x:60062,<,RCPT TO:<recipient@domain.net> ORCPT=rfc822;*****@*****,

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,46,10.0.1.19:25,x.x.x.x:60062,<,DATA,

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,47,10.0.1.19:25,x.x.x.x:60062,>,250 2.1.0 Sender OK,

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,48,10.0.1.19:25,x.x.x.x:60062,>,250 2.1.5 Recipient OK,

2016-01-25T21:37:47.605Z,EXCHANGE01\Default EXCHANGE01,address,49,10.0.1.19:25,x.x.x.x:60062,>,354 Start mail input; end with <CRLF>.<CRLF>,

2016-01-25T21:37:47.683Z,EXCHANGE01\Default EXCHANGE01,address,50,10.0.1.19:25,x.x.x.x:60062,-,,Remote

Can't receive email from certain domains with Exchange 2010

$
0
0

Hello,

I have recently ran into a problem with my Exchange 2010 server. I can not receive emails from certain domains. There is only 2 domain names in particular (only one user from each domain has tried sending emails to our domain).

thanks in advance

Rules that forward to an account that forwards to an outside account issue.

$
0
0
So we are having a situation where the User sets up a rule to forward emails that contain certain keywords in a senders address.  When this rule is valid, they want to forward this email automatically to an outside email address. We have created that email address in exchange server.  If i take an email message and manually forward to that email address, it works great. However if the rule forwards to that email address, it forwards to the internal email address but it stops there and won't forward to the outside address.  Is there a setting that needs to be checked to allow this to happen? or is this just not possible to do?

Set of users unable to recieve emails

$
0
0
It is observed that only a set of users are unable to recieve emails and their outlook status shows disconnected . Other users in the same office are able to send/recieve fine . The exchange database is mounted and is working fine. What could be the possible troubleshooting steps to rectify these ?

User Email account added to the distribution list by the owner but user cannot be seen in the Distribution List

$
0
0

User Email account added to the distribution list by the owner but user cannot be seen in the Distribution List and not receiving the email. However, when expanding the DL on the outlook then only the user email gets display.Issue is happening on Exchange Server 2010 Environment.


Malware filter on Exchange 2013

$
0
0
I understand that filter malware inExchange remove allmailthat comesto the service transport of themailboxservers, Can I display any record of thatmailtransportservicethrough aSMTPDiag?I need to know ifI getone of themailboxservers

I am not able to send mail to external domain and also not receiving mail from external like gmail.

$
0
0

Delivery has failed to these recipients or distribution lists:

trainee.shivani@ifciventure.com Your message wasn't delivered because of security policies. Microsoft Exchange will not try to redeliver this message for you. Please provide the following diagnostic text to your system administrator.

Sent by Microsoft Exchange Server 2007

Diagnostic information for administrators:

Generating server:ifciventure.com

trainee.shivani@ifciventure.com #550 5.7.1 Delivery not authorized, message refused ##

Distribution Group Sender Restrictions Not Working

$
0
0
I've created a new distribution list via the ECP and added myself to it.  In the list's details, under delivery management, I have 'Only senders inside my organization' ticked. However, when I send an email from an external gmail address, it goes through.  What am I doing wrong?

Proper relay connector settings for internal 'inside senders only' distribution groups

$
0
0
I feel like I'm missing something really simple on this. I recently changed our backup reports to go to a newly created distribution group. That group is set to 'Only senders inside my organization' which is how I want it configured. The reports do not get delivered, but if I change the group to 'Senders inside and outside of my organization' it works fine. All servers are internal. I do have a internal relay setup and it is using anonymous access which is used to deliver external mail for various web portals. The backup software does allow for authentication of mail and the other options are server IP and port so I'm guessing this is more of an Exchange connector issue.

Outbound delivery failure to mail.protection.outlook.com

$
0
0

I just migrated from Exchange 2003 to new Exchange 2010 server (and will proceed immediately to Exchange 2013; I was just using 2010 as the required hop between 1003 and 2013). Now we are getting NDRs ("The server has tried to deliver this message, without success, and has stopped trying.") back for outbound messages--but only for those addressed to <RecipientDomain>-com.mail.protection.outlook.com addresses (hosted Exchange, right?)

I checked mxtoolbox.com, which revealed no blacklist for my gateway IP address. These messages were not blocked previously (i.e. on our Exchange 2003)--which was behind the same gateway.

Is there something in the default Exchange 2010 setting that the hosted Exchange domains do not like?

Viewing all 3660 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>