Solved

Exchange not forwarding mails for external domains. 554: Sender address rejected: Access denied

Posted on 2008-06-19
13
3,767 Views
Last Modified: 2013-11-30
I have an Exchange-server, where I have setup mails for some accounts to forward to an external address (xx@instantemail.t-mobile.de). The option "Deliver messages to both forwarding address and mailbox" is set. The reason for forwarding to this external address is that the users are then able to get a copy of their mails on their Blackberry.

This setup has been working perfectly until recently. My current problem is this:
All internal mails (sent from a domain on the exchange-server) are correctly delivered to both the internal and the external mailbox.
All mails sent from an external domain are successfully delivered to the mailbox on the exchange-server, but are not forwarded to xx@instantemail.t-mobile.de.

The users get NDRs like the following:
"There was a SMTP communication problem with the recipient's email server.
<mylocalserver #5.5.0 smtp;554 <the_sender>: Sender address rejected: Access denied>"

I have found the mail in Exchange, where I can see the following information (this mail was sent to 2 local users):
SMTP: Message Submitted to Advanced Queing
SMTP: Started Message Submission to Advanced Queue
SMTP: Message Submitted to Categorizer
SMTP: Message Categorized and Queued for Routing
SMTP: Message Categorized and Queued for Routing
SMTP: Message Queued for Local Delivery
SMTP: Started Outbound Transfer of Message
SMTP: Message Routed and Queued for Remote Delivery
SMTP: Message Delivered Locally to multiple recipients
SMTP Store Driver: Message Delivered Locally to Store to user@mydomain.xx
SMTP: Non-Delivered Report (NDR) Generated
SMTP Store Driver: Message Delivered Locally to Store to user@mydomain.xx

I have a provider in front of my mail-server, who scans for virusses and spam. They have a web-interface, where I can see the complete flow of mails. The forwarded mail does not show up there, which makes me think, that the mail never leaves my exchange-server.

To summarize: Why are mails from external domains not forwarded as they should?
0
Comment
Question by:HenrikDK
  • 4
  • 3
  • 2
  • +1
13 Comments
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 21820777
how are the global settings configured?
was this forwarding working fine before?
0
 
LVL 25

Expert Comment

by:kieran_b
ID: 21820905
>><mylocalserver #5.5.0 smtp;554 <the_sender>: Sender address rejected: Access denied>"

Show us that line with "better" obfuscation

By which I mean something like this (make it as accurate as you can)

<<<myserver.mydomain.com or mydomain.com or mydomain.local>>> #5.5.0 smtp;554 <<email address? Username? IP address?>>: Sender address rejected: Access denied>"
0
 

Author Comment

by:HenrikDK
ID: 21821142
rakeshmiglani:
By global settings, what are you specifically thinking about? As far as I know, this server is running pretty much as default. By looking in "Message Delivery properties", not much is enabled (no sender filtering, connection filtering or recipient filtering. Block messages with an SCL >7, no action. If Sender-ID fails, accept)
Yes, this forwarding has been running smoothly for a long time, and only stopped working a couple of days ago.

kieran_b:
Sure, I'll try to write that line in further detail (the first part is translated from Danish, but the 554 SMTP-error is originally in English):
      xx@instantemail.T-Mobile.de on 18-06-2008 13:15
            There was a SMTP communication problem with the recipient's email server. Please contact your system administrator.
            <master.MyDomain.local #5.5.0 smtp;554 <email-address (xx@xx.de)>: Sender address rejected: Access denied>

Thank you for helping me with this issue, I appreciate it. Please let me know if any additional information is needed.
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 21821177
i was looking for the enabled options under the advanced tab in internet message formats
0
 

Author Comment

by:HenrikDK
ID: 21821244
rakeshmiglani:

In "Internet Message Formats" I have only 1 row:
Name: Default, Domain: *

In the advanced tab, the following options are enabled:
Allow delivery reports
Preserve sender's display name on message.
The following options are disabled:
Allow out of office responses
Allow automatic replies
Allow automatic forward
Allow non-delivery reports

NDRs were disabled yesterday, since users were thinking their mails didn't reach the recipient.
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 21821257
was the "Allow automatic forward" disabled recently or has it been that way since long?
0
 

Author Comment

by:HenrikDK
ID: 21821345
I was thinking that too, and I have asked another admin, who has access to the server, if he has changed the setting. I am still awaiting his reply.

I can try enabling it, but if I understand correctly, it only affects client-side forwarding (http://exchangepedia.com/blog/2008/02/how-to-forward-mail-to-external-email.html)
0
 

Accepted Solution

by:
HenrikDK earned 0 total points
ID: 21854177
The update on this case is as follows:

Our external provider, who scans both outgoing and incoming mails for spam/viruses, recently disabled relaying for unknown domains.
Since we were using their server as smart-host, it rejected mails from all external domains. The solution for now has been to stop using them as a smart-host.
0
 

Expert Comment

by:larsagen
ID: 21898591
I have the same problem, i removed the smarthost( virus112). Then it works fine 2 weeks. Then it starts again. We use virus112 for spam an virus filtering.
0
 

Expert Comment

by:larsagen
ID: 21902260
I have still the problem. After we stop using smarthost it only worked for 14 days. So I need to get a solution. Maybe HenriDK have the same experience.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
When you’re making plans to join the modern business race, you should analyze various details that may affect your results. Nowadays, millions of businesses are trying to grow into established and appreciated professional enterprises.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

822 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question