Link to home
Start Free TrialLog in
Avatar of John-S Pretorius
John-S PretoriusFlag for United States of America

asked on

External emails being bounced from our exchange server

Good Day,

We suddenly started having problems with emails sent from anywhere else but our own domain to be bounced back to the sender as undeliverable. Local Group emails are still being received and we within the doman can send emails just fine.

We are running a Server with Exchange installed on it, and the only drastic change that has been incorporated is email addresses user being created to send Remote event messages outside our offices at locations without creating accounts on the server itself, I'm not sure why the email maessages actually gets send without an account being created on the server but they do.

We have about 15 sites, each one a different email address and set up to do POP over SMTP using the Administrative password and site email address as username - -I never had to create a username on the server.

This part has been functional for about a week now, since yesterday all emplyees within our domain is not receiving any email from senders outside our domain.

Can anyonep lease assist,


Regards,


John-S
Hi. This is the qmail-send program at yahoo.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
 
<SteveM@aptchicago.com>:
205.234.223.160 does not like recipient.
Remote host said: 550 5.1.1 <SteveM@aptchicago.com>: Recipient address rejected: User unknown in relay recipient table
Giving up on 205.234.223.160.
 
<mattm@aptchicago.com>:
205.234.223.160 does not like recipient.
Remote host said: 550 5.1.1 <mattm@aptchicago.com>: Recipient address rejected: User unknown in relay recipient table
Giving up on 205.234.223.160.

Open in new window

Avatar of kieran_b
kieran_b
Flag of Australia image

Can you clearly describe how you are sending mail?

It looks as though you are relaying from the exchange to another server - 205.234.223.160 - that server may well require authentication (they may have just enforced it)

Without a better understanding of what is going on, I can't be sure.
Avatar of John-S Pretorius

ASKER

The emails that gets bounced is coming from anywhere external, you should see this by sending an email to : johnsp@aptchicago.com.

As for the Remote event messaging we are using a Skidata Parking management SOFTWARE PACKAGE THAT USES a 3rd party mail sender SMS SDK that sends out emails using POP over smtp, this part is still functional and I'm just not sure if this could have caused a problem a week later after being set up.

You specify that the mail server may have just enforced it - Could it be that we are being blocked due to emails being relayed from oor locations without being setup on the Exchange server.
So this is you receiving mail and not your sending mail?
Within our Remote event message set-up from all our locations with a user being set-up without being created on the exchange server I receive email from each location as johnsp@aptchicago.com but will send maybe as msisupport@aptchicago.com

As for our exchange server setup we are setup as in a normal exchange enviroment with our domain being aptchicago.com.

I hope this answers your question as I'm not completely sure what it is you are asking.

Currently nobody is receiving mail from anyone externally send to our domain.

Thanks
>>Currently nobody is receiving mail from anyone externally send to our domain.

Got it, that answered my question.

After doing a bit of testing, johnsp seems to be receiving, but mattm isn't - the server that is rejecting it is servershost.net - you will need to check with them and find out why it is not rejecting your mail - it is a problem on their server, not yours.
Thank you, can you please tell me how you you ran this test as we have about another 10 users saying they are not getting any external emails.

As a test, I sent an email from my Yahoo account - I physically only got 2 error replys for mattm and SteveMielke as for the rest - no error reply but they never received the email in their inbox.

Any ideas - we might be getting close.
Hi. This is the qmail-send program at yahoo.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
 
<SteveM@aptchicago.com>:
205.234.223.160 does not like recipient.
Remote host said: 550 5.1.1 <SteveM@aptchicago.com>: Recipient address rejected: User unknown in relay recipient table
Giving up on 205.234.223.160.
 
<mattm@aptchicago.com>:
205.234.223.160 does not like recipient.
Remote host said: 550 5.1.1 <mattm@aptchicago.com>: Recipient address rejected: User unknown in relay recipient table
Giving up on 205.234.223.160.
 
--- Below this line is a copy of the message.
 
Return-Path: <dronkdoos@yahoo.com>
Received: (qmail 11125 invoked by uid 60001); 29 May 2008 05:11:33 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=s1024; d=yahoo.com;
  h=X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:Cc:MIME-Version:Content-Type:Message-ID;
  b=bY7obBrwKFKEVQLPssn4QbxrPJVcRBtKAURMprmYMshczXo529Srgf5rwQqbDJpufh8ivxgfPmzfRl4+wmt/XpOGM7KlzBLg7guwdKCbm6PJnDknMEPvu4HHghxDrKExoNyPxXM9+HjYwZb5UTiBNhGmshb8viwrV+ny3vfzbEg=;
X-YMail-OSG: nNE5bJIVM1kN5ivPBsw2GBBU_Y02rl1OfftjlvvpvB1gWKbnoeXwYw9Gcx.vN_K5o_GfpJe6IWaOriTtmQuyKi0Zya.LIbZ53A--
Received: from [196.41.124.8] by web81404.mail.mud.yahoo.com via HTTP; Wed, 28 May 2008 22:11:33 PDT
X-Mailer: YahooMailRC/975.41 YahooMailWebService/0.7.185
Date: Wed, 28 May 2008 22:11:33 -0700 (PDT)
From: John-S Pretorius <dronkdoos@yahoo.com>
Subject: APT Test
To: mikeh@aptchicago.com, Eric Risch <ericr@aptchicago.com>,
  Mike Boerman <mikeb@aptchicago.com>, Rick Grinker <rickg@aptchicago.com>,
  luker@aptchicago.com, mattm@aptchicago.com, SteveM@aptchicago.com
Cc: John-S Pretorius <john@tswelopele.co.za>, johnsp@aptchicago.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1884197219-1212037893=:1893"
Message-ID: <160744.1893.qm@web81404.mail.mud.yahoo.com>

Open in new window

http://www.zmailer.org/mxverify.html

Put their email address in there - if you get the "recipient address rejected" message, then it is a problem with your mail host.

If you are not getting any error, but you are not getting the mail, then we can start looking at your system.  First stop, the logs of the POP3 connector that you are presumably using.
We are not using POP3 if I'm not mistaken, it is turned off we are using outloook exchange connection or setup thru outlook.
Guys, thank you I am getting closer to the solution I believe - but at this stage it seems that I am not recieving the email sent from external users, I have no idea where they are going as I am not getting mail to bounce anymore.

How do I troubleshoot the exchange server why these emails are not being delivered to their mail boxes?

Remember we are using outlook exchange to connect and not POP3 MAIL IS NOT BEING DELIVERED TO THE USERS.

Please help.
How does your exchange server receive mail?  Because it sure doesn't receive it directly.  There are 2 possible ways.  It is being forwarded by whoever that host is, which is unlikely, or you are using the POP3 connector - DO NOT confuse that with a POP3 server.

A pop3 connector will download mail from another server and import it into your exchange server.

Until we find out how mail is getting onto your server, I can't tell you where to troubleshoot.
MX records from our service provider SBC Ameritech is being routed directly to our domain : aptchicago.com

I found quite some errors looking into the Small bussiness server monitor - the issues started yesterday based on the timestamps of the  messages.

Where else shoul I lookinto?
Source Event ID Last Occurrence Total Occurrences 
  POP3 Connector 1023 5/28/2008 10:30 AM 27 * 
The downloading process for mailbox <johnsp [mail.aptchicago.com]> was ended with one or more errors.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  POP3 Connector 1036 5/28/2008 10:30 AM 27 * 
An error occurred during a POP3 transaction to server <mail.aptchicago.com [johnsp]>. The error is 10060 (A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. ).  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeTransport 348 5/28/2008 10:12 AM 1 
A message could not be virus scanned - this operation will be retried later. Internet Message ID <5B6388D432A34B67AAB6B244DE2440B1@APTLLC.local>, Error Code 0x0. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeDSAccess 2103 5/28/2008 9:53 AM 1 
Process MAD.EXE (PID=2744). All Global Catalog Servers in use are not responding: apt.APTLLC.local For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeAL 8026 5/28/2008 9:53 AM 3 * 
LDAP Bind was unsuccessful on directory apt.APTLLC.local for distinguished name ''. Directory returned error:[0x51] Server Down. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeAL 8250 5/28/2008 9:53 AM 1 
The Win32 API call 'DsGetDCNameW' returned error code [0x862] The specified component could not be found in the configuration information. The service could not be initialized. Make sure that the operating system was installed properly. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  vmauthd 100 5/28/2008 9:53 AM 1 
Small Business Server cannot display a description for this event. For more information, see the Event Log. 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeDSAccess 2104 5/28/2008 9:52 AM 1 
Process INETINFO.EXE (PID=1956). All the DS Servers in domain are not responding. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeDSAccess 2102 5/28/2008 9:52 AM 1 
Process MAD.EXE (PID=2744). All Domain Controller Servers in use are not responding: apt.APTLLC.local For more information, click http://www.microsoft.com/contentredirect.asp.  
 

Open in new window

I found quite some errors looking into the Small bussiness server monitor - the issues started yesterday based on the timestamps of the  messages.

Where else shoul I lookinto?
Source Event ID Last Occurrence Total Occurrences 
  POP3 Connector 1023 5/28/2008 10:30 AM 27 * 
The downloading process for mailbox <johnsp [mail.aptchicago.com]> was ended with one or more errors.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  POP3 Connector 1036 5/28/2008 10:30 AM 27 * 
An error occurred during a POP3 transaction to server <mail.aptchicago.com [johnsp]>. The error is 10060 (A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. ).  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeTransport 348 5/28/2008 10:12 AM 1 
A message could not be virus scanned - this operation will be retried later. Internet Message ID <5B6388D432A34B67AAB6B244DE2440B1@APTLLC.local>, Error Code 0x0. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeDSAccess 2103 5/28/2008 9:53 AM 1 
Process MAD.EXE (PID=2744). All Global Catalog Servers in use are not responding: apt.APTLLC.local For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeAL 8026 5/28/2008 9:53 AM 3 * 
LDAP Bind was unsuccessful on directory apt.APTLLC.local for distinguished name ''. Directory returned error:[0x51] Server Down. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeAL 8250 5/28/2008 9:53 AM 1 
The Win32 API call 'DsGetDCNameW' returned error code [0x862] The specified component could not be found in the configuration information. The service could not be initialized. Make sure that the operating system was installed properly. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  vmauthd 100 5/28/2008 9:53 AM 1 
Small Business Server cannot display a description for this event. For more information, see the Event Log. 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeDSAccess 2104 5/28/2008 9:52 AM 1 
Process INETINFO.EXE (PID=1956). All the DS Servers in domain are not responding. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
 
 
 
 
Source Event ID Last Occurrence Total Occurrences 
  MSExchangeDSAccess 2102 5/28/2008 9:52 AM 1 
Process MAD.EXE (PID=2744). All Domain Controller Servers in use are not responding: apt.APTLLC.local For more information, click http://www.microsoft.com/contentredirect.asp.  
 

Open in new window

Right, so you ARE using the POP3 connector then.

Run through this -> http://support.microsoft.com/kb/885685
I appreciate your time, and asume you are making this statement based on the error you saw in my prevuous attatchment. By trying to get things going I enabled the POP3 connector which will explain the conclusion but just so I understand, if you are using MX records being routed to our Server do you still need a POP3 connection? use the MX Records? please excuse my lack of knowledge as this is not my field of expertiese

and if that is the case, by enabling POP3 didn't maybe I mess things up? Is there a possibility that I messed up the DNS routing and need to clear the cache? - I guess I'M CLUTCHING AT STRAW BUT AT THIS STAGE HAVE BECOME VERY FRUSTRATED.

please share your thougths on MX records being forwarded and the POP3 connector fetching the email just so we are clear.
ASKER CERTIFIED SOLUTION
Avatar of kieran_b
kieran_b
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you much. I understand this better now, I will troubleshoot using the link you sent earlier - knowledge is power, and I can only learn from this.

If there is any more advise to be given I will appreciate it, and even though we have not solved the issue completely I believe your assistance deserves the points, for whatever that is worth - Thank you again, if there is no other comments within the next 20 minutes I will assume I can close this issue and contact my service provider or change to another Hosting company.

Thanks again.
You are more than welcome to leave this open and continue to ask questions if you like.

I am not simply here for the points, knowing that the world makes a little more sense for someone else out there having problems is a reward in itself ;)
Anyone else willing to take a crack at this please - I am willing to allow for a LogmeIn session to look where the problem lies.

Please.
Hey, I've been following this, but thought it best left it in Kieran's capable hands - Just wanted to point out that I totally agree with him - I've had similar (not the same though!) problems in the past at various companies, and my first place to start was generally the ISP.

Let them look into it and see if they can find any problems at their end first, to try and keep things clear as to what's been checked and what hasn't. See what they say and maybe post anything they come back to you with?

Also, a word of WARNING - Be VERY careful about allowing some random from the internet remote control of your server. Remember they have the power of whatever account the server is logged on with. Personally, I'd pay a consultant to take a look over letting someone from the web have access to my server... :)

Anyway, sorry my post is by no means suggesting an actual fix, but I really think you should speak to your ISP first and see what they say...

Pete
Thanks for posting though Pete - I always welcome other posters opinions (especially when they agree with mine - but not only then) :)

John, remote access to your server is not something that is advisabled or recommended here - it is against the rules for one, and HIGHLY dangerous.

I agree with Pete - if you are that desperate, either hire someone or call Microsoft.
Thank you guys, Well noted. I will start by taking it up with our service provider.

Thanks again for the advise.
No problem, that was my way of saying that I was going to join in earlier, but realised that you're clearly cleverer than me so I bowed out... :)

John - See what they say (I doubt they'll be able to resolve this issue completely, as it doesn't sound like the problem solely resides on their end) but it's the strongest place to start. Sometimes resolving one issue can lead on to resolving the next, especially when you're in a muddle.

One step at a time as they say - sometimes trying to resolve everything at once will cause more problems than resolutions!

But post whatever your ISP says back here, I'll be keeping an eye out and you can bet I'll throw in my pennies worth if Kieran's not about... :)
This question was answered correctly under the information at hand, I ended uo resolving the issue with our host and ISP service profider.

Thank you helping me understand the procces, knowledge is worth more than mostly anything else.