Dear colleges,
I need your help on this one because my troubleshooting got me nowhere.
The situation:
Sender outside of our organization sent us one E-Mail which was supposed to be received by Recipient A, but instead gets received by Recipient B. So A never got the E-Mail, but B which does not have any connection with A gets the E-mail. We are currently in the process of migration from EX 2010 to 2016 and so far the mailboxes are 95% finished but still on 2010, SCP is on 2016. Incoming mail goes first through 2010 and 2010 Server forwards the mail to 2016 Server DAG. We use Trendmicro IMSVA for scanning our E-Mails and XiTrust for encryption of our E-Mails.
A and B do not have any mailbox delegation set between them.
E-Mail Properties:
Received: from mx01.OURCOMPANY.com (IP) by OURSERVER.domain
(10.6.100.88) with Microsoft SMTP Server id 14.3.361.1; Thu, 8 Mar 2018
08:55:23 +0100
Received: from mx01.OURCOMPANY.com (unknown [127.0.0.1]) by IMSVA
(Postfix) with ESMTP id C18054E070 for <RECIPIENTA@OURCOMPANY.com>;
Thu, 8 Mar 2018 08:55:22 +0100 (CET)
Received: from mx01.OURCOMPANY.com (unknown [127.0.0.1]) by IMSVA
(Postfix) with ESMTP id 9AF334E06F for <RECIPIENTA@OURCOMPANY.com;
Thu, 8 Mar 2018 08:55:22 +0100 (CET)
Received: from SENDER@Email.com (unknown [IP OMMITED]) by
mx01.OURCOMPANY.com (Postfix) with ESMTPS for
<RECIPIENTA@OURCOMPANY.com; Thu, 8 Mar 2018 08:55:22 +0100 (CET)
Received: from GT-EXCHANGE2010.SENDER.LOCAL
([fe80::4155:dc72:973d:c0c4]) by GT-EXCHANGE2010.SENDER.LOCAL
([fe80::4155:dc72:973d:c0c4%16]) with mapi id 14.02.0387.000; Thu, 8 Mar 2018
08:54:48 +0100
From: SENDER <SENDER@Email.com>
To: "'RECIPIENTA@OURCOMPANY.com'"
<RECIPIENTA@OURCOMPANY.com>
Subject: Question
Thread-Topic: Question
Thread-Index: AdO2Hxh+GAU/A=
Date: Thu, 8 Mar 2018 07:54:48 +0000
Message-ID: <SENDER@Email.com>
References: <1598.124201.152043JavaMail.MAIL ENCRYPTING SERVER$@MAIL ENCRYPTING SERVER>
<SENDER@Email.com>
In-Reply-To: <SENDER@Email.com>
Accept-Language:en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [10.0.1.37]
Content-Type: multipart/related;
boundary="_007_0C34459E615A904196413F18F391D80GTEXCHANGE2010g_";
type="multipart/alternative"
MIME-Version: 1.0
X-TM-AS-GCONF: 00
X-TM-AS-Product-Ver: IMSVA-9.1.0.1631-8.2.0.1013-23706.005
X-TM-AS-Result: No--19.100-4.5-31-10
X-imss-scan-details: No--19.100-4.5-31-10
X-TM-AS-User-Approved-Sender: No
X-TM-AS-User-Blocked-Sender: No
X-TMASE-Version: IMSVA-9.1.0.1631-8.2.1013-23706.005
X-TMASE-Result: 10--19.100400-10.000000
X-TMASE-MatchedRID: OoEa6u7Uk...
X-IMSS-DKIM-White-List: No
X-TMASE-SNAP-Result: 1.821001.0001-0-1-12:0,22:0,33:0,34:0-0
Return-Path: SENDER@Email.com
X-MS-Exchange-Organization-AuthSource: OURSERVER.domain
X-MS-Exchange-Organization-AuthAs: Anonymous
X-EXCLAIMER-MD-CONFIG: ba9bbaa9-6f85-4be2-a9d9-b5432a15d57f
X-MS-Exchange-Organization-AVStamp-Mailbox: SMEXtG}w;1380100;0;This mail has
been scanned by Trend Micro ScanMail for Microsoft Exchange;
X-MS-Exchange-Organization-SCL: 0
In Exchange 2010 Tracking logs explorer I could not find anything that could point me to the cause of the issue. There is this one thing where I get a defer message:
But here the "EventData" field is empty, I tried the command on 2016 but did not get the result. I
Is there another way to take a look why did this situation happen?
Thank you,