Quantcast
Channel: Exchange Server 2013 - Mail Flow and Secure Messaging forum
Viewing all 1480 articles
Browse latest View live

Exchange server 2013 send and received issue

$
0
0

Hi Support,

I have install Exchange Server 2013 with server 2012 ( my domain not resisted but mail send & received in local for practice then live ) but few days back some changes in dns and ecp and mail stop sending and receiving. how to verify my exchange server 2013 working fine. Please give the step check perpoes.     


filters for retentions policies in OWA

$
0
0

I created new retention policy 'Move messages older then 180 days'

my Retention Policy works good but I need setup some filters

filter for some email boxes

filtered emails should stay in Inbox folder and does not move into archive folder

how I can do it ?

thanks

RBL Blocklist Providers and Spam filtering - Best practices

$
0
0

Good day all

I am very new to the Microsoft forums so please point me in the right direction if this question does not fall under this category.

I have been assigned to administer an Exchange 2010 server, there is no edge transport server, running version 14.01.0438.000, with Microsoft outlook as the clients software.

This Exchange environment has been implemented at the beginning of this year. We have had numerous complaints about spam received on a daily basis. Our network has all the necessary firewalls and antivirus in place. A Gateprotect Firewall, Avast endpoint for the servers and Avast email server security running on the Exchange 2010 server. I have configured the RBL blocklist providers in the content filtering and checked the logs to see if they are playing their roles. I have seen a major decrease in spam when the Avast email server security application was installed but there is still spam slipping through the cracks. The types of spam that i see everyday varies.

Examples:

  • Emails about dating, weight loss,viagra, business investments etc. 
  • Emails received that's addressed to an unknown person outside of the organization.
  • Emails received by many users in the organization that was not addressed to them but the send to address is a legitimate account within our organization.

On the Exchange server i have enabled the anti spam content filtering along with all the other filters in the organizational tree, hub transport, anti-spam tab. I set the SCL ratings - Delete = 9, reject = 7 and quarantine = 5 (created a junk mail account). Is this correct?

There are two RBL blocklist providers in the IP blocklist providers properties, zen.spamhaus.org and bl.spamcop.net. I was told not to add more blocklist providers as they will slow down the Exchange server.Is this true?Can i add in additional IP addresses and ranges to the IP blocklists in the Server configuration tree, hub transport and anti-spam tab?

The Avast Email Server Security has limited options. I have enabled the "delete spam" option and there is only a blacklist and whitelist to add in email addresses and domain names.

The Gateprotect Firewall also has limited features for fighting spam, only blacklists and whitelists. The support guys has recommended some work arounds but i am not that advanced in configuring firewalls at that level.

When tracking the IP address of spam emails that has the same heading and the same text in the body but their email addresses are different and their IP addresses are completely different,how do i block those types of spam?

With email addresses that has been "spoofed", i read up that in order to block that from occurring i would need to add in SPF records in the Control panel for our domain.What needs to be done there?

Please assist me with understanding the ways of fighting spam and what more i can do to improve the system.

Thank you in advance. 

SSL Certificates - how to...?

$
0
0

Hey Guys,

I need some help in SSL management in Exchange 2013. I have 2 CAS servers and 2 Mailboxes servers installed with wildcard certificate for clients. When I am looking into Servers -> Certificates in ECP I see several certificates assigned to SMTP service. Why there is several certificates assigned to same service? How can I check which one is valid? How to clear it up? Several certificates assigned to same service is confusing me a little bit... And I have no idea how to clean it up without breaking anything :)

IP getting listed in blocklist again and again. Mail bounched back.

$
0
0

I have exchange server 2010. whenever some particular hosts send emails on particular email IDs, their mail are bounced back with this error:

mx1.aliyun-inc.com rejected your message to the following e-mail addresses:

 

Michael Lau /sorter machine (michael@ahhongshi.net.cn)

 

mx1.aliyun-inc.com gave this error: Reject by behaviour spam at DATA State(Connection IP address:111.93.52.26)ANTISPAM_BAT[01201311R2166S321, r46d02014]: unexpected sending

 

A problem occurred during the delivery of this message to this e-mail address. Try sending this message again. If the problem continues, please contact your helpdesk.

 

merry (merry@ahhongshi.net.cn)

 

mx1.aliyun-inc.com gave this error: Reject by behaviour spam at DATA State(Connection IP address:111.93.52.26)ANTISPAM_BAT[01201311R2166S321, r46d02014]: unexpected sending

 

A problem occurred during the delivery of this message to this e-mail address. Try sending this message again. If the problem continues, please contact your helpdesk.

 

 

 

 

 

 

 

Diagnostic information for administrators:

 

Generating server: MAILSERVER.century.local

 

michael@ahhongshi.net.cn mx1.aliyun-inc.com #554 Reject by behaviour spam at DATA State(Connection IP address:111.93.52.26)ANTISPAM_BAT[01201311R2166S321, r46d02014]: unexpected sending ##

 

merry@ahhongshi.net.cn mx1.aliyun-inc.com #554 Reject by behaviour spam at DATA State(Connection IP address:111.93.52.26)ANTISPAM_BAT[01201311R2166S321, r46d02014]: unexpected sending ##

 

Original message headers:

 

Received: from MAILSERVER.century.local ([fe80::bc93:5f89:3a50:2815]) by  mailserver.century.local ([fe80::bc93:5f89:3a50:2815%10]) with mapi id  14.02.0247.003; Fri, 19 Sep 2014 10:17:50 +0530 From: Century Imports <imports@centuryinfrapower.com> To: Century Imports <imports@centuryinfrapower.com>, "Michael Lau  /sorter  machine" <michael@ahhongshi.net.cn>, merry <merry@ahhongshi.net.cn> Subject: SCAN COPY OF ORIGINAL DOCUMENTS REQUIRED Thread-Topic: SCAN COPY OF ORIGINAL DOCUMENTS REQUIRED Thread-Index: AQHP0LnsQf73yLm8GEm8+MVx4PzHcJwCJV4AgAKkACCAAYNbMIABm3eg Date: Fri, 19 Sep 2014 04:47:50 +0000 Message-ID: <B255D6F31C28164A9FDEDB612D3CFE92791F6DF4@mailserver.century.local> References: <B255D6F31C28164A9FDEDB612D3CFE926063C834@mailserver.century.local>,          <2014072809101581254714@ahhongshi.net.cn>,         <201408191712037811106@ahhongshi.net.cn>,          <201408221511192855241@ahhongshi.net.cn>,         <B255D6F31C28164A9FDEDB612D3CFE9270993E27@mailserver.century.local>,         <201408221545055356231@ahhongshi.net.cn>,          <B255D6F31C28164A9FDEDB612D3CFE9270993E46@mailserver.century.local>,         <201408221648356130215@ahhongshi.net.cn>,          <201408281721027183179@ahhongshi.net.cn>,         <201409011603127033940@ahhongshi.net.cn>,          <B255D6F31C28164A9FDEDB612D3CFE9271DE0E8C@mailserver.century.local>,         <2014090311483693708629@ahhongshi.net.cn>,          <B255D6F31C28164A9FDEDB612D3CFE9276F3FDE4@mailserver.century.local> <2014091515454764000832@ahhongshi.net.cn>   Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: yes X-MS-TNEF-Correlator: x-originating-ip: [192.168.0.125] Content-Type: multipart/related;         boundary="_008_B255D6F31C28164A9FDEDB612D3CFE92791F6DF4mailservercentu_";         type="multipart/alternative" MIME-Version: 1.0

 

I am using port 25 for sending email. I have also configured a block rule on firewall which blocks port 25 for all hosts except servers. I also scanned all hosts by AV but no virus found. what to do now. Open SMTP relay is also disabled on server.. Please help


prdeepkumawat

dns setting require for mail server 2013

$
0
0

Hello Support,

I have install exchange server 2013 and working fine but right now i have some change in DNS server record and my mail services stop. what record add to start my mail services ( sent and received). till now exchange server mail box give the error mail not connected with server. Please revered ASAP.   

receive email problem

$
0
0

Hello,

I try telnet email test but i have this error. How i can fix it?

451 4.7.0 Temporary server error. Please try again later. PRX4

i tried DNS settings , Host file update , ReCreate Receive Connectors but all failed.

Detailed logs ;

D:\Exchange\TransportRoles\Logs\FrontEnd\ProtocolLog\SmtpReceive

Message or connection acked with status Retry and
response 451 4.4.0 Primary target IP address responded with: ""501
5.5.4 Required arguments not present."" Attempted failover to
alternate host, but that did not succeed. Either there are no alternate hosts,
or delivery failed to all alternate hosts.

D:\Exchange\TransportRoles\Logs\FrontEnd\Connectivity

2013-11-29T11:04:36.130Z,08D0BB050818EAC4,SMTP,internalproxy,-,Messages: 0 Bytes: 0 (Retry : Required arguments not present)

2013-11-29T11:05:12.724Z,08D0BB050818EAC6,SMTP,internalproxy,+,Undefined 00000000-0000-0000-0000-000000000000;QueueLength=<no priority counts>

There's a problem with the recipient's mailbox. Please try resending this message.

$
0
0

I have a user who cannot receive a message from a particular external sender. That senders assistant (same domain and server as the external sender with the issue) is able to forward the exact same message to my user and it arrives as it should. In message tracking, I can see the message came in through my smart host, through my front end and to the users mailbox server, where an NDR was generated.  We had the assistant forward us the NDR and it says:

There's a problem with the recipient's mailbox. Please try resending this message. If the problem continues, please contact your helpdesk.

From my 3rd party smart host/spam filter, I have a copy of the message in audit and when I forward it to myself, the same thing happens - it generates an NDR when it arrives at my Exchange mailbox server.  This makes me conclude that my end users mailbox isn't corrupt, rather it's something in the message header that our server doesn't like (I've seen this happen with other senders as well, but it is extremely rare and random).

Details/facts of my environment:
-Current production messaging system is Exchange 2003.
-Working on Exchange 2010 co-existence.
-This problem between this sender and us has been an issue before the introduction of Exchange 2010.
-I'm hoping to begin end user mailbox migrations to 2010 and will have the sender try again at that time, but I still have testing to do with our voice messaging system before I can begin moving end user mailboxes.

....Begin redacted NDR detail....
Remote Server returned '< #5.2.1>'
Original message headers:
Received: from fe.mydomain.com ([192.168.1.10]) by
 mailboxsrv.mydomain.com with Microsoft SMTPSVC(6.0.3790.4675);      Thu, 4 Sep
 2014 12:49:48 -0700
Received: from exc2010.mydomain.com ([192.168.1.50]) by
 fe.mydomain.com with Microsoft SMTPSVC(6.0.3790.4675);        Thu, 4 Sep
 2014 12:49:47 -0700
Received: from smtp.mydomain.com (192.168.1.49) by exch2010.mydomain.com
 (192.168.1.50) with Microsoft SMTP Server (TLS) id 14.3.210.2; Thu, 4 Sep 2014
 12:49:47 -0700
Received: from pps.filterd (PPMail.mydomain.com [127.0.0.1])   by
 PPMail.gsblaw.com (8.14.5/8.14.5) with SMTP id s84Jkb0n023682       for
 <myuser@mydomain.com>; Thu, 4 Sep 2014 12:49:47 -0700
Received: from na01-by2-obe.outbound.protection.outlook.com
 (mail-by2on0098.outbound.protection.outlook.com [TheirIP])    by
 PPMail.gsblaw.com with ESMTP id 1p6da7h0jw-1 (version=TLSv1/SSLv3
 cipher=AES256-SHA bits=256 verify=NOT)       for <Myuser@mydomain.com>; Thu, 04 Sep
 2014 12:49:42 -0700
Received: from Theirexchange.theirdomain.com (TheirinternalIP) by
 Theirexchange.theirdomain.com (TheirinternalIP) with Microsoft SMTP
 Server (TLS) id 15.0.1019.16; Thu, 4 Sep 2014 19:49:38 +0000
Received: from Theirexchange.theirdomain.com ([10.141.86.14]) by
 Theirexchange.theirdomain.com ([TheirinternalIP]) with mapi id
 15.00.1019.015; Thu, 4 Sep 2014 19:49:38 +0000
Content-Type: multipart/mixed;
        boundary="_000_9a166afd24964edda2d5439ba3dbe712DM2PR08MB445namprd08pro_"
From: Mr Sender <sender@theirdomain.com>
To: My User <myuser@mydomain.com>, "Another external recipient (someoneelse@anotherdomain.us)"
        <mike@vinco.us>
Subject: FW: A Subject
Thread-Topic: A Subject
Thread-Index: Ac/C2zn97ruwXQpoQtGNrjKOr1NckgFmNoeAAAEpQ2A=
Date: Thu, 4 Sep 2014 19:49:37 +0000
Message-ID: <9a166afd24964edda2d5439ba3dbe712@DM2PR08MB445.theirexchange.theirdomain.com>
References: <3340b0a848f04e3bbb488b4eda93d54e@DM2PR08MB445.theirexchange.theirdomain.com>
 <83FC8FC0E8B91C4594608EA214C0BBAD54BBB844@S1P5DAG8C.EXCHPROD.USA.NET>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: <9a166afd24964edda2d5439ba3dbe712@DM2PR08MB445.theirexchange.theirdomain.com>
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [internetIP]
x-microsoft-antispam: BCL:0;PCL:0;RULEID:;UriScan:;
x-forefront-prvs: 0324C2C0E2
x-forefront-antispam-report: SFV:NSPM;SFS:(10009015)(6009001)(189002)(199003)(377454003)(164054003)(64706001)(66066001)(19609705001)(15202345003)(50986999)(19300405004)(19625215002)(90102001)(80022001)(20776003)(83322001)(101416001)(99936001)(76176999)(54356999)(81542001)(21056001)(19580395003)(86362001)(4396001)(92566001)(16236675004)(85852003)(551944002)(74502001)(83072002)(87936001)(74662001)(31966008)(107886001)(81342001)(76482001)(46102001)(85306004)(105586002)(33646002)(15975445006)(99396002)(76576001)(74316001)(77982001)(79102001)(95666004)(108616004)(2656002)(106356001)(99286002)(24736002);DIR:OUT;SFP:1101;SCL:1;SRVR:DM2PR08MB446;H:DM2PR08MB445.namprd08.prod.outlook.com;FPR:;MLV:sfv;PTR:InfoNoRecords;MX:1;A:1;LANG:en;
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.12.52,1.0.27,0.0.0000
 definitions=2014-09-04_03:2014-09-04,2014-09-04,1970-01-01 signatures=0
X-Proofpoint-Spam-Reason: safe
Return-Path: sender@theirdomain.com
X-OriginalArrivalTime: 04 Sep 2014 19:49:47.0046 (UTC) FILETIME=[61900460:01CFC879]


I cannot sent e-mails on the new installation exchange server 2013

$
0
0
I tried everything sent connector , DNS configuration. Internally works fine and I can receive e-mail , but when I'm sending e-mails out of the domain they all stuck on queue with code 451.4.4.0. 

Restrict Allow Acces to Distribution List

$
0
0

Dear All

My boss asked me a unique query in managing DL and I am not able to find the answer anywhere on net.

Scenario

Suppose there are 5 DL's in our organization for eg

TestGroup1

TestGroup2

TestGroup3

TestGroup4

TestGroupALL

Requirement

My boss ask me following

1) Allow TestGroup1 members to only send mail to TestGroup1 and TestGroupALL, sending mail to all other DL's are restricted

2) Same for all 2, 3 4 group members who can only send to their respective DL's and TestGroupALL

3) TestGroupAll Contains all above 1 to 4 DL's so any member can send mail to TestGroupAll and it should be received by all users in organization.

I hope there will be some solution to this, kindly suggest one..

Regards

Sandesh

How to send email to a SMTP server over a secure channel using STARTTLS setting of a send connector (Exchange and SMTP server are in the same domain)

$
0
0

I’m trying to send email using exchange send connector STARTTLS setting to the SMTP server. I have read multiple documents on configuring TLS for send connector, but they talks about outbound connections to internet facing servers. My Exchange 2013 and SMTP server is in the same domain (let’s say A.com) and I’m creating dummy domains on my SMTP server (e.g. user1@dummy1.local, user2@dummy2.local ) and their respective send connectors on the exchange server end. In the smart host section added the IP address of the SMTP server and in the scoping section added the SMTP domain address (e.g. dummy1.local ). In the FQDN field, added the FQDN of the exchange server 2013 which certificate is enabled with SMTP service.

Could you tell me a step by step procedure, where I’m going wrong or any extra settings needs to added?

Presently, it is giving me an error that 530 5.5.1 TLS encrypted connection is required.

Note: I’ve created the Microsoft CA certificates for the SMTP and exchange servers and imported them in the personal certificate container. In which, the exchange certificate is created with FQDN name of the server and enabled for the SMTP service.

I’m using OPENSSL certificate for making the SMTP server TLS enabled. (let me know, if I need to import the OPENSSL certificate anywhere on the exchange end)?

Thanks!


Exchange 2013 DLP Testing - Allowing Social Security numbers

$
0
0
I've created a DLP policy to block SSN's.  The problem is it only looks for the word "SSN".  The rule in the DLP is looking for SSN's.  It blocks the email if I have the letters "SSN" in it with a fake social, but if I remove the letters "SSN" it allows it to send.  Is there a way to tune how it reads sensitive info?

ST

Edge Server vs Hub Transport

$
0
0

Hi all,

is there any different with anti spam between Edge Transport and Hub Transport in Exchange 2013 ? 

Any software or 3rd party solution for anti spam beside FOPE for Exchange 2013 ?


Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. Krisna Ismayanto | My blogs: Krisna Ismayanto | Twitter:@ikrisna

Restrict Allow Acces to Distribution List

$
0
0

Dear All

My boss asked me a unique query in managing DL and I am not able to find the answer anywhere on net.

Scenario

Suppose there are 5 DL's in our organization for eg

TestGroup1

TestGroup2

TestGroup3

TestGroup4

TestGroupALL

Requirement

My boss ask me following

1) Allow TestGroup1 members to only send mail to TestGroup1 and TestGroupALL, sending mail to all other DL's are restricted

2) Same for all 2, 3 4 group members who can only send to their respective DL's and TestGroupALL

3) TestGroupAll Contains all above 1 to 4 DL's so any member can send mail to TestGroupAll and it should be received by all users in organization.

I hope there will be some solution to this, kindly suggest one..

Regards

Sandesh

receive email problem

$
0
0

Hello,

I try telnet email test but i have this error. How i can fix it?

451 4.7.0 Temporary server error. Please try again later. PRX4

i tried DNS settings , Host file update , ReCreate Receive Connectors but all failed.

Detailed logs ;

D:\Exchange\TransportRoles\Logs\FrontEnd\ProtocolLog\SmtpReceive

Message or connection acked with status Retry and
response 451 4.4.0 Primary target IP address responded with: ""501
5.5.4 Required arguments not present."" Attempted failover to
alternate host, but that did not succeed. Either there are no alternate hosts,
or delivery failed to all alternate hosts.

D:\Exchange\TransportRoles\Logs\FrontEnd\Connectivity

2013-11-29T11:04:36.130Z,08D0BB050818EAC4,SMTP,internalproxy,-,Messages: 0 Bytes: 0 (Retry : Required arguments not present)

2013-11-29T11:05:12.724Z,08D0BB050818EAC6,SMTP,internalproxy,+,Undefined 00000000-0000-0000-0000-000000000000;QueueLength=<no priority counts>


451 4.4.0 dns query failed. The error was: DNS Query failed with error ErrorRetry Exchange 2013

$
0
0

Hi,

We are using MS Exchange Server 2013 CU1 on MS Windows Server 2008 Standard R2. 

In queue viewer, I am getting this error for few domains only "451 4.4.0 dns query failed. The error was: DNS Query failed with error ErrorRetry"

Any because of this, We are unable to send any email to these domains, 

Can someone please help to fix this..?

Thanks in Advance..


Thanks, Manoj

Exchange 2010 to 2013 Migration- orphaned 2010 servers in Edge subscription

$
0
0

Migration of Exchange 2010 to 2013 was carried out.  Steps to decommission the 2010 servers was done, including removing the Exchange software fro the servers.  Looks like some pieces were missed though as the 2010 servers still appear in the smarthostdelivery and shadow redundancy on the 2010 edge transport server.

How can these be removed?

Exch 2013 Forwarding Mail from local account to External SMTP user

$
0
0

New 2013 implementation... Two Servers (Front End and Back End) both running Exchange 2013.

I am having trouble sending a local AD Exchange mailbox mail to external SMTP address.  I have tried several options.. I have created an "contact" as was required in previous versions.  I have created new AD accounts with external SMTP addresses, I have also attempted to use the scriptlet:

Set-Mailbox -Identity "%AD-USER%" -DeliverToMailboxAndForward $true -ForwardingSMTPAddressexternaluser@mail.com  (%AD-USER% was actual AD Username/mailbox) andexternaluser@mail.com was actual receipient SMTP address (username@gmail.com)

Local AD Mailbox receives the mail appropriately however I have enabled forwarding everyway I know how and nothing seems to work.  If I send mail straight from my account to the destination SMTP address, they get it; just not if it is sent to the local AD account then forwarded via -DeliverToMailboxAndForward command...

Please help.. I have several users that I need to have their mail CC'd to an external SMTP address.. Previous versions of Exchange required a "Contact" to be created and then the mailbox forwarded to that contact, which had a SMPT mail address...

Im not adverse to implementing via powershell if I can just get it to work... Any suggestions are greatly appreciated and needed.

certain extensions blocked

$
0
0

The users regularly need to browse sites in the .uk   Also they email to the .uk extension.

I cannot figure out how to permanently allow such access and email usage.

I have added .uk to allow list but at first it worked and now it does not.

We are using Exchange 2010

Thanks,

Jay


Jay Doyle

HealthMailbox....... thousands of tranfers appearing in SPAM quarantine

$
0
0

I've asked this question on another forum without an answer so I thought I would try here.

This relates to Exchange 2013.  During Friday through to Monday I am picking up thousands of spam items sent frominboundproxy@inboundproxy.com and up to five HealthMailboxes are involved.  The healthmailboxes have accounts in AD and appeared during the Exchange installation.

Here is and example -

Diagnostic information for administrators:

Generating server: EXCHANGE2.xxxxx.yyyyyyyy.yy.yy

HealthMailbox168a97e4814144848b101e39c3482fca@xxxxx.yyyyyyyy.yy.yy
#550 5.2.1 Content Filter agent quarantined this message ##

Original message headers:

Received: from EXCHANGE2.xxxxx.yyyyyyyy.yy.yy (192.168.0.72) by
 EXCHANGE2.xxxxx.yyyyyyyy.yy.yy (192.168.0.72) with Microsoft SMTP Server
 (TLS) id 15.0.516.32; Mon, 19 Nov 2012 19:20:48 +0000
Received: from InboundProxyProbe (::1) by EXCHANGE2.xxxxx.yyyyyyyy.yy.yy
 (::1) with Microsoft SMTP Server id 15.0.516.32 via Frontend Transport; Mon,
 19 Nov 2012 19:20:48 +0000
Subject: Inbound proxy probe
Message-ID: <2e1d9dd2-d71e-4c23-9b5a-b8e12c109e57@EXCHANGE2.xxxxx.yyyyyyyy.yy.yy>
From: <inboundproxy@inboundproxy.com>
To: Undisclosed recipients:;
Return-Path: inboundproxy@inboundproxy.com
Date: Mon, 19 Nov 2012 19:20:48 +0000
MIME-Version: 1.0
Content-Type: text/plain
Received-SPF: Fail (EXCHANGE2.xxxxx.yyyyyyyy.yy.yy: domain of
 inboundproxy@inboundproxy.com does not designate ::1 as permitted sender)
 receiver=EXCHANGE2.xxxxx.yyyyyyyy.yy.yy; client-ip=::1;
 helo=InboundProxyProbe;

 
Can anyone spread light on this, is it normal behaviour and if not how can I stop it?  The exchange installation is on a green field domain.  The exchange server is an OOTB installation on a single VM.






Viewing all 1480 articles
Browse latest View live




Latest Images