Channel: Exchange Server 2013 - Mail Flow and Secure Messaging forum
Viewing all 3660 articles
Browse latest View live

Issue when sending email to a mail enabled security group



We have Exchange Server 2013 in our environment.I had created a mail enabled secuirty group.Inside this groups are few other mail enabled security groups. Basically a group was created with nested groups. There are altogether around 60 users within this group from different databases.

When an email was sent to this group, only 13 users received the email. For others mail delivery failed without any NDR to sender.The email was delivered to 13 random users within the group from different databases.

Kindly suggest me if anyone has faced similar issue and how should I resolve this.


Exchange 2013



Our Microsoft Organisation id :4358894

WE have exchange exchange Server 2013. Some reason its not sending and receiving any email . only internally email works.

Please give me a call on +447949432338 or +447951375571 so that you can remotely login and resolve email problems.

Kind Rgards,

Syed Rahman

Exchange 2013 no connection to domain, maiday



Our Exchange cannot connect to the domain any more:

Process Microsoft.Exchange.Directory.TopologyService.exe (PID=2320). The Exchange computer dc.domain.LOCAL does not have Audit Security Privilege on the domain controller dc.domain.LOCAL. This domain controller will not be used by Exchange Active Directory Provider.

All domaincontrollers seem to be allright, dcdiag is succsessfull on all DC's but fails on Exchange computer.

Regards Gudjon

Regards Gudjon

OriginalFromAddress not being added to Sender field


Hi there,

I have a security camera NVR that is sends an email when it wants attention, but our Exchange server keeps telling me the sender address is blank, so the messages get quarantined.

The logfile Microsoft\Exchange Server\V15\TransportRoles\Logs\Hub\ProtocolLog\SmtpReceive looks normal;

<,MAIL FROM:<NVR@mydomain.local> SIZE=0 AUTH=<>,

but by the time it gets to the tracking log, it looks like this;

MessageSubject: Test Mail
Sender             :     
ReturnPath       : NVR@mydomain.local
Directionality    : Incoming

and the EventData looks like this;

Key   : OriginalFromAddress
Value : NVR@mydomain.local

Key   : AccountForest
Value : mydomain.local

Key   : PurportedSender
Value : mydomain.local NVR@mydomain.local

Any ideas what could be causing this, and how i go about fixing it?

Relay does not work after server in other site owns databases


Hi All,

We have a distant site and an exchange server in the site which is a part of our DAG. Cluster owner is the server in our site. we moved all the DBs there , there are some applications that rely on relay and they are unable to send emails externally while emails internal recipients is fine. while the smtp gateway cannot see the traffic of emails sent from the applications when we emails sent from a mailbox the email is delivered to the external recipient.

Help is appreciated.



Not yet delivered email


Our email can't send and recieved email to specific one domain. Previously it working properly. 

Here is the details.

Office 365 received the message that you specified, but delivery to the recipient (example@domain) has been delayed. We're working on delivering it.

This is the last record we have for the message: In process

More Information

Check the Message Events table below for any additional information about why message delivery might be delayed. For example, it might be due to a temporary issue trying to connect to the recipient's email server outside of Office 365. Many such delays clear up on their own, and the message gets delivered. If Office 365 isn't able to send or deliver the message within 48 hours, the sender will receive a non-delivery report (NDR) message with more information about how to fix the issue.

If you don't want to wait for the message to finish being processed, consider asking the sender to send the message again using a different email address.

Reason: [{LED=450 4.1.8 <sample@ourdomain.com>: Sender address rejected: Domain not found};{MSG=};{FQDN=w00f5969.kasserver.com};{IP=};{LRT=10/15/2019 7:34:07 AM}]. OutboundProxyTargetIP: OutboundProxyTargetHostName: w00f5969.xxxserver.com

Exchange 2013 CU21 + Edge stripping .xlsx


I confirmed the attachment filter does not have a .xlsx entry added. I disabled all entries, restarted the transport service, and resent the source file. It was still stripped.

I wasn't able to locate a reason in the logs here, or anywhere else:

Edge Server: C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\Edge\ProtocolLog\SmtpSend


Disabling the attachment filter agent allows file to pass, so I was able to get a copy of the affected source file.

I am able to successfully send personal .xlsx files, so to me, it's how this particular .xlsx is being generated.

This FIXES my issue, but I'm on EX2013 CU21



I extracted a normal .xlsx and compared the [Content_Types].xml

New .xlsx


    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>

    <Types xmlns="http://schemas.openxmlformats.org/package/2006/content-types">

        <Default Extension="rels" ContentType="application/vnd.openxmlformats-package.relationships+xml"/>

        <Default Extension="xml" ContentType="application/xml"/>

        <Override PartName="/xl/workbook.xml" ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.sheet.main+xml"/>

        <Override PartName="/xl/worksheets/sheet1.xml" ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.worksheet+xml"/>

        <Override PartName="/xl/theme/theme1.xml" ContentType="application/vnd.openxmlformats-officedocument.theme+xml"/>

        <Override PartName="/xl/styles.xml" ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.styles+xml"/>

        <Override PartName="/docProps/core.xml" ContentType="application/vnd.openxmlformats-package.core-properties+xml"/>

        <Override PartName="/docProps/app.xml" ContentType="application/vnd.openxmlformats-officedocument.extended-properties+xml"/>



Stripped .xlsx


    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>

    <Types xmlns="http://schemas.openxmlformats.org/package/2006/content-types">

        <Default ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.printerSettings" Extension="bin"/>

        <Default ContentType="image/png" Extension="png"/>

        <Default ContentType="application/vnd.openxmlformats-package.relationships+xml" Extension="rels"/>

        <Default ContentType="application/xml" Extension="xml"/>

        <Override ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.sheet.main+xml" PartName="/xl/workbook.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.worksheet+xml" PartName="/xl/worksheets/sheet1.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.theme+xml" PartName="/xl/theme/theme1.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.styles+xml" PartName="/xl/styles.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.sharedStrings+xml" PartName="/xl/sharedStrings.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.drawing+xml" PartName="/xl/drawings/drawing1.xml" />

        <Override ContentType="application/vnd.openxmlformats-package.core-properties+xml" PartName="/docProps/core.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.extended-properties+xml" PartName="/docProps/app.xml" />

        <Override ContentType="application/vnd.openxmlformats-officedocument.custom-properties+xml" PartName="/docProps/custom.xml" />



What gives?

Tagging Internal and External email



I have setup two Transport rules to to tag INTERNAL and EXTERNAL email messages. Once this done, and the Transport service restarted, I got the desired results. Except now, if anyone replies to an email, each time the INTERNAL tag is applied to the Subject line. This creates a mess. Is there a way to stop INTERNAL being applied each time to the message? I have tried the Exception "Except when the Subject field contains specific words" with INTERNAL being the word, but no luck. Is there something else I can do?


Stephen Keating  

Stephen Keating

Emails from scanner with user's email address as a sender are going to Junk


Hi there,

I have several scanners with the same config, which send emails to Exchange server. Scanners are configured to send emails with a user as a Sender and a Receiver. The problem is that from one particular scanner emails are detected as Junk. Obviously users can't add their own email addresses to Whitelist. From other scanners all good. Any idea where can be the problem?



SMTP transient error: 421 Service not available


I am facing interim issue with my oracle DB. where smtp relay is working for 99% of emails sent but only 1% being sending failed with error "SMTP transient error:421 Service not available". I am unable to trace any log entry for missed emails at exchange end in smtp receive logs.

please guide how to trace and resolve the issue. both my server are available not network connectivity issue. ping telnet trace won't show any outage or disconnect.



Exchange Server 2013 and ms-Exch-SMTP-Accept-Authoritative-Domain-Sender


Hello, Team!

I think I’ve found a serious issue in last CU releases. This is the case:

1 Multirole server Exchange 2013 SP1 (and older) , one creceive connector from internet to this server, no edge, nothing.

I care about preventing spoofing my company’s email addresses, and remove remove the ms-Exch-SMTP-Accept-Authoritative-Domain-Sender transport permission from anonymous senders.

To do this, we usually simple run powershell command

Remove-ADPermission <ReceiveConnector Name> –user “NT AUTHORITY\Anonymous Logon” –ExtendedRights ms-Exch-SMTP-Accept-Authoritative-Domain-Sender

This command works on Exchange SP1, the client (telnet session, f.e.) which try spoof address of company will be refused. (see screenshot below)

But in Exchange 2013 CU5, CU6 and even CU7 release this revoke permissions DOESN’T WORKS without any errors, softly. I've try Powershell and ADSI but unsuccessfully.

Then we take off permission on connector above, we keep 3 default permissions:



Submit-Message to Server

It is wonderful works only on server SP1, but not on servers with older versions, which have right settings.

The saddest thing is I have information about Office 365 this behavior reproduced too. And I also think what in your lab you could take 15 minutes and play this simply thing....

I found only that information on connector side is diffenent on SP1 and CU5,6,7.

This is normal connection on SP1, when somebody try spoofed address. We can see a 250 AUTH Response on server side, and server refuse fake connection, all right.

And on CU5 and newest versions we doesnt see this code. Maybe auth mechanism miss something?

Any suggestions? On MS connect site a didn't found exchange bugs topic :)

Back Pressure - Submission Queue - Exchange Server 2010


Hello Guys,

Currently we are using Exchange Server 2010 and we had issue in last week with Submission Queue. In Which our Submission Queue start building a queue more than 5,00,000+ of email. we investigated and find out that one of the mailbox due to there system issue has sent these emails (and these emails were alerts) and our 1 HUB server enter to back pressure state.

I have find a lot of articles describing the situation of Back Pressure but didn't find anything related to "When Submission Queue is Under Pressure." currently this issue is resolved. But I am looking any Article or Any possible solutions for Submission Queue is Under Pressure.

Thanks in Advance.

Forwarding emails from one distribution group to another distribution group


Hi everyone,

I have Exchange Server 2013. I want to "Group1" distribution group forwards emails to "Group2" distribution group. I cannot create any rule in Exchange Server.

Unable to configure outlook profile of user - Exchange 2013


Unable to configure outlook profile of user - Exchange 2013

Same user i m able to configure using active sync, but not able to configure in outlook

in exchange mapi is enabled. 

while testing from microsft test connectivity i got the error:

Testing the address book "Check Name" operation for user user@sdomain.com against server 31d652a6-33bf-4304-b814-250aa6944e30@domain.com.
 An error occurred while attempting to resolve the name.
 Tell me more about this issue and how to resolve it
Additional Details
The name could not be matched to a name in the address list.

System Administrator

You dont have permission to send to : GroupName message being prompted in Outlook even though permission is provided



We have Exchange 2010/2013 hybrid environment.  

We have a sensitive email distribution group and delivery is restricted to certain users only.

When a user who is allowed to send mail to this distribution group tries sending mail using outlook, he receive the error message:

You don't have permission to send to : GroupName

Additional Point : This user has multiple mailbox profile in his outlook. Only one of the mailbox in his profile is allowed to send message to this group.

Kindly help me in resolving the issue.

"User & Mailbox are in two different active directory sites" after move the Exchange in different AD site



I have two Active Directory site like SiteA and SiteB. I have three Exchange server 2 for SiteA for DC site and 1 for SiteB for DR site. Mail flow is okay but when I move the 3rd Exchange in SiteB then mail starting go through the 3rd Exchange server and submission failed with error message "Mail routing failed User & Mailbox are in two different active directory sites".



EX2013 & multiple send connectors


I have a home lab setup for learning exchange 2013.

I have setup two email domains dm_test_a.co.uk and dm_test_b.co.uk I have a number of test users setup on each email domain and able to send internal email to each. all seems okay.

I have two internet connections and each have a smart relay of their own and I want dm_test_a.co.uk to relay via isp1 and dm_test_b.co.uk to relay via isp2.

using the send connector I have setup each of the isp's smart relay and each is working when the other is disabled so I am confident that the send connector is correct. however I cannot work out how I assign a send connector to a particular source email domain.


protection.outlook.com dropps connection without any information


Hello all, please help identify the root cause of the issue I'm facing. Since a while back all emails attemted to be sent to any company laveraging Office 365 (connection goes via ***.protection.outlook.com) are failing with no reason provided


Getting responsible mx server
Nslookup mx
> microsoft.com
microsoft.com   MX preference = 10, mail exchanger = microsoft-com.mail.protection.outlook.com
microsoft-com.mail.protection.outlook.com       internet address =

now trying to connect via console
telnet microsoft-com.mail.protection.outlook.com 25
220 BL2NAM06FT003.mail.protection.outlook.com Microsoft ESMTP MAIL Service ready at Thu, 31 Oct 2019 15:47:32 +0000
HELO mx.mydomainhere.ru
(hangs for ~30 sec)
connection closed

That's it! No information at all while trying to send an email.

Here is an example of sending to gmail.com as another example where there are no issues, same as all others not using O365.

nslookup mx
gmail.com       MX preference = 40, mail exchanger = alt4.gmail-smtp-in.l.google.com
alt4.gmail-smtp-in.l.google.com internet address =

telnet alt4.gmail-smtp-in.l.google.com 25
220 mx.google.com ESMTP *** - gsmtp
HELO mx.mydomainhere.ru,
250 mx.google.com at your service,
226086,sending message
MAIL FROM:<***@mydomainhere.ru>,
250 2.1.0 OK *** - gsmtp,
RCPT TO:<***@gmail.com>,
250 2.1.5 OK *** - gsmtp,
354  Go ahead g28si3712191ljn.11 - gsmtp,
250 2.0.0 OK  1572481571 *** - gsmtp,
221 2.0.0 closing connection ** - gsmtp,

Any ideas on how to troubleshoot this? Many thanks

What is the meaning of softfail and what issues it can cause and how to fix it?


What is the meaning of softfail in authentication-result for spf in an email header and what issues it can cause and how to fix it? Does it get fixed on sender's exchange side or recipient's exchange side?

Mail flow for a specific internal domain


Hi everybody. 

A little question for a case I encounter. 
I have a client (let's call it Company A) who's got an Exch2013 Server for emailing.
They just bought a company (let's call it Company B), whose emails are on Zimbra. 

They want to migrate all Company B's mailboxes from Zimbra to Office 365, and keep all the Company A's mailboxes on their existing Exchange 2013 server. 

What I Want : 

- create the domain name of Company B in the existing AD of Company A
- create the Company B's user accounts with their domain name in Company A AD
- populate the mail attribute of the user accounts correctly. 

What do I have to do in my DNS or on the Company A's Exchange server to prevent mail flow errors? Because I can imagine that if I just create the user accounts, the Company A's user will have issues while sending emails to Company B's users. 

Thanks :) 

Viewing all 3660 articles
Browse latest View live

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>