Quantcast
Channel: Exchange Server 2013 - Mail Flow and Secure Messaging forum
Viewing all 3168 articles
Browse latest View live

Exchange mailbox Transport: Delivery and Submission Service wont start.

$
0
0

I have a fresh install of 2 2013 servers  Front CAS and Back MBX role coexistent with 2007.

It was working fine until this weekend when we moved the DNS names to 2013. Meaning we moved owa/ol etc site names in DNS  and adjusted the virtual directories on both 2007 to legacy.xxx.com and mail.xx.com to the new 2013.

What now is happening is the 2 services "microsoft Exchange mailbox transport submission and microsoft exchange mailbox transport delivery services are not starting.. The only error i get is the standard "the service did not respond to the start or control request in a timely fashion."e

Its preventing any 2013 mialbox from send/recieve.  

I have checked and IPv6 is ON, the connectors are scoped ONLY to the IPv4 address. The MBX server is configured with internal/external DNS and the send connector is using external DNS.  I found that here http://social.technet.microsoft.com/Forums/exchange/en-US/26cc797d-6a40-4e18-bdb9-0e0387a12da1/the-microsoft-exchange-mailbox-transport-submission-service-terminated-unexpectedly 

Need help resolving this as its preventing moving anymailboxes to it.. All other services are working OWA proxy to 2007 etc and mail flow to and from 2007 are all working..


Thanks, Grady Vogt


mysterious sender in SENT mail

$
0
0
We recently got our company set up with a MS Exchange server (2007) for all of our company email. My boss has his email forwarded to a different email address that is hosted on a different server entirely. I was troubleshooting an issue and was looking at the SENT mail message tracking log. In the sender column there were some strange email addresses I had never seen before, and certainly not tied to our company (SPAM). The recipient was my boss' email on the other server and the return path showed his email address on the exchange server and the sender was a spammy unrecognized address. Does this mean his account is hacked? I tried to research this question and saw a lot of people saying to make sure our server isn't an open relay. I already checked this, and no it is not.

Exchange 2007 - proxyAddresses and external mail server.

$
0
0

Hi all,

I've got an issue with Exchange 2007 and an Exchange Online mail service (Office365). I was pointed here for additional assistance. The issue is Exchange 2007 users cannot mail Office365 users. I have verified it's not on the Office365 end as I can send and receive emails from other services such as Google Mail.

Background:

We have 3 domains, I'll name them as colors to distinguish them and for privacy reasons. Here's the list with their purpose:

  • white.local.lan - internal domain
  • red.com - Faculty Email Domain (Exchange 2007) and Website Domain
  • blue.com - Students Email Domain (Exchange Online via Office365)

We have created a UPN suffix of blue.com in order to match them with the Office365 domain. All students are assigned this suffix. We have created records in the proxyAddresses attribute of Active Directory for the purpose of DirSync via Forefront Identity Manager. This is working well.

Every time we send an email to an address in the proxyAddresses attribute we get bounce messages as follows:

Delivery has failed to these recipients or distribution lists:

{EMAIL ADDRESS}

There's a problem with the recipient's mailbox. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.

_____

Sent by Microsoft Exchange Server 2007 

Diagnostic information for administrators:

Generating server: {INTERNAL EXCHANGE SERVER}

{EMAIL ADDRESS}

#550 5.2.0 RESOLVER.ADR.BadPrimary; recipient primary SMTP address is missing or invalid ##

We have set up the following in Exchange 2007:

[Organization Configuration] -> [Accepted Domains]

Accepted Domain: blue.com
Default: False
After MSEXCH Accepts: External Relay Domain

[Organization Configuration] -> [Send Connectors]

GENERAL
Protocol Logging Level: None
Specify the FQDN this connector will provide in response to HELO or EHLO:<blank>
Max Message Size (KB): 10240

ADDRESS SPACE
Type: SMTP
Address: blue.com
Cost: 1
Scoped Send Connector: unchecked / no

NETWORK
Select how to send mail with this connector: Use domain name system (DNS) "MX" records to route mail automatically
Enable Domain Security (Mutual Auth TLS): unchecked / no
Use the External DNS Lookup Settings on the transport server: checked / yes

SOURCE SERVER
Name:<Exchange Hostname>
Site: <Site Name>
Role: Mailbox, Client Access, Hub Transport



anonymous senders on default recieve connector

$
0
0

Hi there,

I am struggling with understanding security implication of the anonymous permission on the default receive connector. I am looking for a steer in the right direction:)

I have exchange 2010 SP3 stand alone server with hub transport behind a firewall (no edge). We do have a 3rd party service (spam filter) that relays clean emails to our exchange server.

Currently i have a default setup receive connector that is configured to receive emails for any IP and a rule in the firewall to relay traffic on port 25 to the exchange server.

Recently i came to realization that all of my internal devices such as multi functional printers, UPS, NAS, etc are able to send notification emails to me without any authentication involved. That would mean, if say a virus hit any of my client computers, it would have a green light to spam everyone internally or externally without much effort!

Is this correct?

Obviously, if i uncheck anonymous permission in default receive connector, my server won't be able to receive anything at all.

Are there any best practices to secure this flaw? limit which anonymous INTERNAL devices can use my exchange as a relay? how about External anonymous clients, is it a concern?

#554 5.4.4 SMTPSEND.DNS.NonExistentDomain; nonexistent domain ##

$
0
0

#554 5.4.4 SMTPSEND.DNS.NonExistentDomain; nonexistent domain ##<o:p></o:p>

Original message headers:<o:p></o:p>

Received: from HPSERVER.STINDIA.COM (192.168.0.200) by HPSERVER.STINDIA.COM<o:p></o:p>
 (192.168.0.200) with Microsoft SMTP Server (TLS) id 15.0.516.32; Thu, 22 Aug<o:p></o:p>
 2013 13:22:31 +0530<o:p></o:p>
Received: from HPSERVER.STINDIA.COM (192.168.0.200) by HPSERVER.STINDIA.COM<o:p></o:p>
 (192.168.0.200) with Microsoft SMTP Server id 15.0.516.32 via Frontend<o:p></o:p>
 Transport; Thu, 22 Aug 2013 13:22:24 +0530<o:p></o:p>
Received: from 203.201.252.2 ([203.201.252.2])       by HPSERVER.STINDIA.COM<o:p></o:p>
 (HPSERVER.STINDIA.COM)        (MDaemon PRO v13.0.0)  with MultiPOP id<o:p></o:p>
 md50000007628.msg     for <>; Thu, 22 Aug 2013 13:19:27 +0530<o:p></o:p>
X-Spam-Processed: HPSERVER.STINDIA.COM, Thu, 22 Aug 2013 13:19:27 +0530     (not<o:p></o:p>
 processed: domain stindia.co.in is excluded from spam filtering)<o:p></o:p>
X-MDMultiPOP: <o:p></o:p>
X-Rcpt-To: <o:p></o:p>
X-MDRcpt-To: <o:p></o:p>
X-MDRemoteIP: 203.201.252.2<o:p></o:p>
X-Envelope-From: <o:p></o:p>
Received: from in.outbound.mailhostbox.com ([115.114.58.25]) by<o:p></o:p>
 rapidwebdns.com with MailEnable ESMTP; Thu, 22 Aug 2013 13:18:06 +0530<o:p></o:p>
Received: from kamlesh (static-mum-59.181.158.178.mtnl.net.in<o:p></o:p>
 [59.181.158.178])     (Authenticated sender:      by<o:p></o:p>
 in.outbound.mailhostbox.com (Postfix) with ESMTPA id 91D5D1680260   for<o:p></o:p>
<>; Thu, 22 Aug 2013 07:48:19 +0000 (GMT)<o:p></o:p>
Message-ID: <o:p></o:p>
Reply-To: "Steel Tubes India - Kamlesh D. Jain" <o:p></o:p>
From: "Steel Tubes India - Kamlesh D. Jain" <o:p></o:p>
To: "Steel Tubes [India] - Sales" <<o:p></o:p>
Subject: EMAL<o:p></o:p>
Date: Thu, 22 Aug 2013 13:18:53 +0530<o:p></o:p>
Organization: Steel Tubes India - Kamlesh D. Jain<o:p></o:p>
MIME-Version: 1.0<o:p></o:p>
Content-Type: multipart/mixed;<o:p></o:p>
        boundary="----=_NextPart_000_00FC_01CE9F3A.25E61BC0"<o:p></o:p>
X-Priority: 3<o:p></o:p>
X-MSMail-Priority: Normal<o:p></o:p>
Importance: Normal<o:p></o:p>
X-Mailer: Microsoft Windows Live Mail 15.4.3555.308<o:p></o:p>
Disposition-Notification-To: "Steel Tubes India - Kamlesh D. Jain"<o:p></o:p>
      <o:p></o:p>
X-MimeOLE: Produced By Microsoft MimeOLE V15.4.3555.308<o:p></o:p>
X-CTCH-RefID: str=0001.0A0C0207.5215C244.0108,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0<o:p></o:p>
X-CTCH-VOD: Unknown<o:p></o:p>
X-CTCH-Spam: Unknown<o:p></o:p>
X-CTCH-Score: 0.000<o:p></o:p>
X-CTCH-Rules:<o:p></o:p>
X-CTCH-Flags: 0<o:p></o:p>
X-CTCH-ScoreCust: 0.000<o:p></o:p>
X-CTCH-SenderID: <o:p></o:p>
X-CTCH-SenderID-TotalMessages: 1<o:p></o:p>
X-CTCH-SenderID-TotalSpam: 0<o:p></o:p>
X-CTCH-SenderID-TotalSuspected: 0<o:p></o:p>
X-CTCH-SenderID-TotalBulk: 0<o:p></o:p>
X-CTCH-SenderID-TotalConfirmed: 0<o:p></o:p>
X-CTCH-SenderID-TotalRecipients: 0<o:p></o:p>
X-CTCH-SenderID-TotalVirus: 0<o:p></o:p>
X-CTCH-SenderID-BlueWhiteFlag: 0<o:p></o:p>
X-ME-Bayesian: 15.583860<o:p></o:p>
X-MDRedirect: 1<o:p></o:p>
X-MDRedirect_From:<o:p></o:p>
X-Return-Path:<o:p></o:p>
X-MDaemon-Deliver-To: <o:p></o:p>
Return-Path: <o:p></o:p>

Relaying Mail From DMZ Standalone Server to Exchange 2003

$
0
0

Greetings everyone,

First, my apologies for posting a 2003 question in a 2013 forum, but the categories provided are 2013-only.

I have a standalone Windows 2008 R2 server with SMTP services and a custom app that generates email.  I would like to create a domain entry on the SMTP service so messages that are destined for corporate recipients get sent from the DMZ directly to the corporate Exchange 2003 server.  The Exchange server seems to be refusing connections from the standalone server even if I add its IP to the relay list; I don't get an error, the connection seems to timeout.  Does anyone know how would I go about getting this working with some security?

Thanks in advance for your help,

S_B

Exchange 2013: How To Change Email Attachment Size Limit

$
0
0

I think I can change it through ECP on Send/Receive Connectors, right? I know that's for Message Size Limit, not for Attachment, but I think there's not a big difference as for my case.

After changing it, what services I need to restart to make it work?

Thanks.


Lawrence Fung

Exchange 2013 SMTP limits

$
0
0

We recently upgraded from an Exchange 2007 server to an Exchange 2013 server. We recreated the relays as best we could and now we have a couple of our users that are experiencing issues. They use an outside bulk email web service when they have to send updates to many of their clients (usually @ 100 - 300) and they can now only send to 5 clients at a time.

The way it works is they input their email address through the web service, our SMTP address, and authenticate through us. It then sends out the emails using our relay so it goes out as them and provides the delivery report of who was sent the email. Since the move to Exchange 2013 they are now limited to 5 at a time and show "Delivery successful" while the rest show as:

"Delivery Failure, Expected "250", Instead Reported 421 4.4.2 Message submission rate for this client has exceeded the configured limit"

I have made changes using the Get-ReceiveConnector and changed the MessageRateLimit from 5 to 50 and it still does not work. I even changed them all (unnecessary, but getting desperate) to unlimited at one point to test and it still only allows 5 at a time.

I realize this is a configuration setting somewhere, I just can't find it. Any direction on this would be appreciated.

~Rick


Exhange 2013 External Inbound Mail routing options

$
0
0

I am planning a migration from a Lotus Notes to Exchange 2013 environment that is site resilient. I understand that there will be a migration period and that the mail routing design will look different during that time of the migration. I have been researching the architecture of Exchange 2013 and I feel I have a pretty good understanding of most features in the CAS and DAG roles but it is really unclear how inbound/outbound external mail routing is configured. In previous versions many people used the Edge Transport server and I can still use the Exchange 2010 Edge Transport server in 2013 as one option. I am also finding information that I can setup send and recieve connectors on the Exchange 2013 CAS servers to do this task too. Below are my questions about this topic.

  1. Am I right that Exchange 2013 CAS or Exchange 2010 Edge Transport are options for this service?
  2. Are there other option for Inbound/Outbound External mail routing with Exchange 2013? Third party or otherwise?
  3. Of all my options what are the pros/cons to using each one.
  4. I have heard rumors of an Exchange 2013 Edge Transport service that is planned for future release? Are there any details on what this will feature, when it will be released, or how it will work?

Web Mail Exchange Server

$
0
0

I just configured my intranet exchange server alongside Server 2012.

Presently, I can successfully send mail to public web mails but on the other hand,

my web mail cant receive mail from the public. I even tried giving it a public IP; still nothing happens.

From my gmail account, error generated is this:

Technical details of permanent failure:
DNS Error: Domain name not found.

Can anyone help, please

SSL cert question(s) Exchange 2013

$
0
0
Hi all.  I have a friend who's replacing his SBS 2003 server with a Windows Server 2012 Standard server with Exchange 2013.  I just want to make sure I understand the cert part of Exchange 2013.

As I understand he needs to get a multi-domain or UCC cert and he'll need certs created for autodiscover.hisdomain.com (hasn't had to use this with 2003), mail.hisdomain.com (was already using this with 2003), and perhaps a cert with the FQDN of the server (hasn't had to use this with 2003).  Does that all sound right?

Also, as I understand it the CSR needs to be created on the new 2013 server, not the existing 2003 server, correct?

Exchange 2013 Spam/AV Options

$
0
0

In a new Exchange 2013 deployment I am trying to understand my options for Spam/AV Filtering for email.  I have read that there is a feature on the Exchange 2013 Mailbox server role that will catch spam. I also read that Microsoft offers a cloud based spam filtering/av scanner service for purchase. Exchange 2010 Edge Transport server appears to be an option yet too. I also know there are many 3rd party tools that can be utilized as well.

Are my research results for my options above correct? Are there any other options I am missing.

How good of a spam filter tool comes with the Exchange 2013 mailbox role?


Separate filter service of exchange?

$
0
0

Hi all,

I have the situation that is:

There is one mail server in form of hosting, and there are five clients at my site using outlook to send and receive mails, my domain is amtech.com. I want to set up a seperate filter service that only allow my client send and receive with domain "amtech.com" without configuring on mail server at hosting site. Is there any way to do that? Thank you

Issues Delivering mail from GMAIL

$
0
0
Hello everyone... we seem to all of a sudden be having issues with messages that have attachments of just about any kind from GMAIL being delivered to us. If there is no attachment, we have no problem -- but put an attachment in and BAM -- it gets bounced with this message: 

Delivery to the following recipient failed permanently: 

me@myhost.com

Technical details of permanent failure: 
Unspecified Error (SENT_MESSAGE): Connection reset by peer 

----- Original message ----- 

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; 
d=gmail.com; s=20120113; 
h=subject:references:from:content-type:message-id:date:to 
:content-transfer-encoding:mime-version; 
bh=mGIlaJ4YTwb6y84VByL+/2pgPQJ3Y+5R+f4h0iU+pE4=; 
b=YHeNUIRfrcWmLZavwRHaeSCFxEI0sxilF1pe9j+B2/T/esItUGtjyiJD6EnzKB2ktZ 
4j+iVegjf1TRVRo2fQEh/2xLbVhYb2mRTjVn/8Qwfk0CbTFx7vDY3t2hpJ872HY/HQsg 
cxd+LDPtDasolPB9kgBIiEfL3ZcOYu0WRWEN+89z9RKDdDjCGhifM9FK4nHqGnkKX0AN 
RKy8Vjr+DSd+wbTFuuKzjyusZ+U/Vb3gMURrMAAaOyk36ey26b3/Iz9L6+9TY7uF1HdU 
3OHnuDLCOFuxZ8iAPben8GwNvaD9LNFODI4YPbbBl5u1+eNSvms95AI9WvrdVIAVhz+f 
rshA== 
X-Received: by 10.224.19.133 with SMTP id a5mr13389398qab.54.1377122840463; 
Wed, 21 Aug 2013 15:07:20 -0700 (PDT) 
Return-Path: <you@yourhost.com> 
Received: from [192.168.1.18] (173-161-220-14-Philadelphia.hfc.comcastbusiness.net. [173.161.220.1]) 
by mx.google.com with ESMTPSA id j11sm13742845qaa.7.1969.12.31.16.00.00 
(version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); 
Wed, 21 Aug 2013 15:07:16 -0700 (PDT) 
Subject: Fwd: Email sent to Me 
References: <CE393F20.32E8B%someone@something.com> 
From: BCPG <BCPG@gmail.com> 
Content-Type: multipart/alternative; 
boundary=Apple-Mail-CA61A01E-B5A7-4A97-A0A7-98055E299372 
X-Mailer: iPhone Mail (10B329) 
Message-Id: <C742A5D3-6A0B-439F-9235-820F8A81AF44@gmail.com> 
Date: Wed, 21 Aug 2013 18:07:12 -0400 
To: Bruce Sarte <me@myhost.com> 
Content-Transfer-Encoding: 7bit 
Mime-Version: 1.0 (1.0) 



I'm confused by the error. Can anyone shed some light on this issue? I am not sure if it is Exchange or a communication error. I've tried to send this same message from a NON-GMail account and it delivers just fine. So that -- generally speaking -- rules out my SPAM filter and various other things... 

We are running Exchange 2010 SP1 on a Win2k8R2 box. 

Anyone help? 

Thanks in advance!

550 4.4.7 Queue expired, Message expired

$
0
0

Hi Guys,

We got NDR for some domains with error code #550 4.4.7 QUEUE.Expired; message expired ##;

So i go to the queue viewer and see some queue stuck there with last error

1. 451 4.4.0 Primary target IP address responded with : "421 4.2.1 unable to connect";

2. 451. 4.4.0 DNS query failded;

Any suggestions for troubleshooting?
If the mails and queues keep failing, will them be deleted or moved to somewhere finally?
As i monitor the queue recently and the queue is always changing, not one specific queue stuck there all the time.

Thanks!


Weicong888


Ayuda me da este error

$
0
0

mx.google.com rechazó su mensaje a las siguientes direcciones de correo electrónico:


mx.google.com produjo este error: [2002:ba65:44b2::ba65:44b2 16] The sender does not meet basic ipv6 sending guidelines of authentication and rdns resolution of sending ip. Please review more information. do3si4234734vcb.123 - gsmtp

El mensaje no se entregó debido a un problema de seguridad o con los permisos. Puede que lo haya rechazado un moderador, que la dirección sólo acepte correo electrónico de determinados remitentes o que haya otra restricción que impida la entrega.

Información de diagnóstico para los administradores:

Generando servidor: SRVDC01.veraquintana.local

 mx.google.com #550-5.7.1 [2002:ba65:44b2::ba65:44b2 16] The sender does not meet basic 550-5.7.1 ipv6 sending guidelines of authentication and rdns resolution of 550-5.7.1 sending ip. Please review 550 5.7.1 more information. do3si4234734vcb.123 - gsmtp ##

Bounce Back Messages Occurring with Exchange Server 2010 - "Please turn on SMTP Authentication in your mail client, or login to the IMAP/POP3 server before sending your message"

$
0
0

I have a Microsoft Small Business Server 2011. About four months ago the OWA stopped working and MS Support had to be called to get it fixed since nothing we did resolved the issue. However after the OWA was repaired we started noticing excessive amounts of email bounce backs occurring, but only during a "reply". In otherwords, if we replied to the sender we would get a bounce back, but if we created a new email with the senders address it went through. This is just totally bizzare. Micorosft Support personnel have looked at this sideways and at this time can't resolve the problem. Yes before anyone askes, we have checked our static IP and domain for blacklists, checked reverse DNS and just about everything external imagineable and it all checks out good. The error message which is contained here thinks we are running POP3 email accounts, when in fact all our email goes through an Exchange Server. So the message is really not helpful at all. Here is the most common of the bounce backs:

Please turn on SMTP Authentication in your mail client, or login to the IMAP/POP3 server before sending your message.  [********]:46408 is not permitted to relay through this server without authentication.

A problem occurred during the delivery of this message to this e-mail address. Try sending this message again. If the problem continues, please contact your helpdesk.

Our ISP as well as other IT folks have looked at this and are puzzled, if you Google the error you get tons of crap that has nothing to do with Exchange Services, but most reference POP3. We have POP3 and IMAP turned off we don't use a Smart Host and everything was fairly fine until the OWA issue occurred.

Everyone I've talked to so far has no clue. I can't be the only one in the known Exchange universe that has run into this before? Any one have any ideas?

exchange 2010\transport rules\How to determine a message has been processed by a specific rule ?

$
0
0

Hi,

I setup a rule to silently delete  message from a specific sender which is working fine.
My issue is, I'm not able to evaluate how many time this specific rule has been triggered. In exchange 2007, there was the possibilty to create an event when a rule was triggered, it disappeared from the gui but there is still-logeventtxt parameter that exist. Unfortunately, I didn't manage to make it works.

From get-messagetracking, I can only see from the source (agent),sourcecontext(transport rule agent) that a message has been processed by a rule, I change the loglevel but it seems I can't identify  nor the rule, nor the frequency of the rule usage. Am I missing something ?

best regards,

Mikaël

Exchange 2010 NDR Relay

$
0
0

We have a server that is setup to relay e-mail through Exchange to students that sign up for classes.  They are e-mailed their username/password to the e-mail address they enter on a web form that the server processes and then sends the e-mail.

If a student enters their e-mail address incorrectly, is there a way to generate an NDR and send it to an Administrator?  Trying to think through this scenario, maybe asking students to enter their e-mail address twice to make sure they've entered it correctly.

I've read some about enabling protocol logging and/or message tracking but that seems tedious and reactive instead of proactive.

Just curious what other options are available...

I can apply RMS transport rules to meeting invitations?

$
0
0

Hi friends, I need to protect content from the organization: I want to apply a Not-Forward rule to mails or Meetings with certain subjects, but I don't know (and I can't find any information about this) if this rule can be applied to a meeting invitation (from Outlook clients is not possible, the "permision" button don't appear when I'm Schedule a meeting), and I need to know if the rule apply to meeting invitations, we want that a meeting invitation can't be forwarded.

Can help me with this? I'm looking for several documents but I can't find anything


Germán Ruiz -- Infrastructure Architect -- Speaker TechNet LATAM -- http://germanruizp.blogspot.com

Viewing all 3168 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>