Solved

NDR on Exchange 2003 - Internal mail bounses to new users, but not older users.

Posted on 2008-10-07
25
216 Views
Last Modified: 2008-10-08
We're using Exchange Server 2003 running on Windows Server 2003.  The mail server has worked perfectly for over a year.  We recently added a new batch of users to the AD.  When sending mail to these new users, we receive an NDR (Exchange error #5.1.1).

The e-mail account does not exist at the organization this message was sent to.  Check the e-mail address, or contact the recipient directly to find out the correct address.
<mail.DOMAIN.COM #5.1.1>

Email sent between the older users still works fine.

The weirdest part of the problem is that when I send two emails to a user in succession, the first will bounce and return an NDR and the second will go through just fine.

We've tried removing users and readding them to the domain and updating and rebuilding the Recipient Update Services.
0
Comment
Question by:rivey_210901
  • 12
  • 11
  • +1
25 Comments
 
LVL 2

Expert Comment

by:emanteuf
ID: 22662938
Last time I saw something like that there was something wrong with the mailbox database.  We fixed it by creating a new mailbox database and moving the users over to the new database.  We then deleted the old database after everything was moved over.  
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22662940
can you pease advise if the RUS auto adds these email addresses and the x400 address?
0
 
LVL 3

Expert Comment

by:cnjuguna
ID: 22662987
check your AD logs to make sure replication is okay. also ensure the mailboxes have been created.
0
 

Author Comment

by:rivey_210901
ID: 22662999
The SMTP, X400 records get added when we create a new account with exchange privlidges.
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663023
is this DC in a differnt domain or site to where the actual exchange server is?
0
 

Author Comment

by:rivey_210901
ID: 22663074
We have noticed that there are replication errors at times, however, we can force the replication and still not get emails to send.   When checking the mailboxes and some of the mailboxes are there, while others are not.  
0
 

Author Comment

by:rivey_210901
ID: 22663077
only one domain.  This dc and 6 other DCs are all in the same network / domain.
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663097
to test create a new test user
force replication on all DCs
connect to all 6 DCs, do you see the AD object with the SMTP address and X400 address which you just created? In ADUC

or atleast see the AD object if ESM isnt installed.
0
 

Author Comment

by:rivey_210901
ID: 22663158
Created a user and verified account after replication to PDC.  However, replication to a different server failed.  
0
 

Author Comment

by:rivey_210901
ID: 22663175
THe replication error references that the time since the last replication has exceeded the tombstone lifetime
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663214
oh dear! ok please can you provide a dcdiag log?

we need to find out which DCs are Tomb stoned
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663229
also please provide how many Global Catalogs you have, how many of the 6 are GC?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:rivey_210901
ID: 22663243
I know the one that is tomb stoned - what do I need to do with it.  It is called AMD-BACKUP and it doesnt really do anything special.  I can demote it if I need to.  Otherwise, please tell me how to produce a "dcdiag log"
0
 

Author Comment

by:rivey_210901
ID: 22663314
5 of 8 (not six sorry) have the global catalog checked.
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663332
was AMD-BACKUP a global catalog?
0
 

Author Comment

by:rivey_210901
ID: 22663347
yes - adm-backup was / is a global catalog.
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663380
to get dcdiag
install support tools on one of the DCs http://www.microsoft.com/downloads/details.aspx?FamilyId=6EC50B78-8BE1-4E81-B3BE-4E7AC4F0912D&displaylang=en
if not already installed

click start > program files > wiindows support tools > command prompt
type dcdiag /f:c:\dcdiag.log

on that same server go to the root of C:
open the dcdiag.log and paste the text here.
0
 

Author Comment

by:rivey_210901
ID: 22663428
ok: here goes:



Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: GilmerISD\GISD-MAIL
      Starting test: Connectivity
         ......................... GISD-MAIL passed test Connectivity

Doing primary tests
   
   Testing server: GilmerISD\GISD-MAIL
      Starting test: Replications
         [Replications Check,GISD-MAIL] A recent replication attempt failed:
            From ADM-BACKUP to GISD-MAIL
            Naming Context: CN=Schema,CN=Configuration,DC=GISD,DC=LAN
            The replication generated an error (8614):
            The Active Directory cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.
            The failure occurred at 2008-10-07 15:25:51.
            The last success occurred at 2008-07-08 09:45:52.
            2154 failures have occurred since the last success.
         [Replications Check,GISD-MAIL] A recent replication attempt failed:
            From ADM-BACKUP to GISD-MAIL
            Naming Context: CN=Configuration,DC=GISD,DC=LAN
            The replication generated an error (8614):
            The Active Directory cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.
            The failure occurred at 2008-10-07 15:25:51.
            The last success occurred at 2008-07-08 09:57:59.
            2154 failures have occurred since the last success.
         [Replications Check,GISD-MAIL] A recent replication attempt failed:
            From ADM-BACKUP to GISD-MAIL
            Naming Context: DC=GISD,DC=LAN
            The replication generated an error (8614):
            The Active Directory cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.
            The failure occurred at 2008-10-07 15:25:51.
            The last success occurred at 2008-07-08 10:00:26.
            2158 failures have occurred since the last success.
         REPLICATION-RECEIVED LATENCY WARNING
         GISD-MAIL:  Current time is 2008-10-07 15:28:00.
            CN=Schema,CN=Configuration,DC=GISD,DC=LAN
               Last replication recieved from ADM-BACKUP at 2008-07-08 09:56:21.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!
            CN=Configuration,DC=GISD,DC=LAN
               Last replication recieved from ADM-BACKUP at 2008-07-08 09:58:08.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!
            DC=GISD,DC=LAN
               Last replication recieved from ADM-BACKUP at 2008-07-08 10:00:26.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!
         ......................... GISD-MAIL passed test Replications
      Starting test: NCSecDesc
         ......................... GISD-MAIL passed test NCSecDesc
      Starting test: NetLogons
         ......................... GISD-MAIL passed test NetLogons
      Starting test: Advertising
         ......................... GISD-MAIL passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... GISD-MAIL passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... GISD-MAIL passed test RidManager
      Starting test: MachineAccount
         ......................... GISD-MAIL passed test MachineAccount
      Starting test: Services
         ......................... GISD-MAIL passed test Services
      Starting test: ObjectsReplicated
         ......................... GISD-MAIL passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... GISD-MAIL passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems.
         ......................... GISD-MAIL failed test frsevent
      Starting test: kccevent
         An Error Event occured.  EventID: 0xC00007FA
            Time Generated: 10/07/2008   15:25:51
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC00007FA
            Time Generated: 10/07/2008   15:25:51
            (Event String could not be retrieved)
         ......................... GISD-MAIL failed test kccevent
      Starting test: systemlog
         ......................... GISD-MAIL passed test systemlog
      Starting test: VerifyReferences
         ......................... GISD-MAIL passed test VerifyReferences
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : GISD
      Starting test: CrossRefValidation
         ......................... GISD passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... GISD passed test CheckSDRefDom
   
   Running enterprise tests on : GISD.LAN
      Starting test: Intersite
         ......................... GISD.LAN passed test Intersite
      Starting test: FsmoCheck
         ......................... GISD.LAN passed test FsmoCheck
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22663477
ok looks like your best bet is to manually remove this server from AD as i dont think you can just use DCpromo to remove it as its hit the tombstone.

does adm-backup hold any of the FSMO roles? if so move/seizr them over to the other DCs.

you are going to needto follow this guide to remove that server manually from AD.

http://www.petri.co.il/delete_failed_dcs_from_ad.htm
0
 

Author Comment

by:rivey_210901
ID: 22663497
ok, will attempt to follow and remove this server. Do you think this would cause the problem we are expericncing with Exchange?  on just the new users?
0
 
LVL 11

Accepted Solution

by:
Bertling earned 500 total points
ID: 22663520
possible, but lets clear up any dcdiag errors first it seems this tombstone has just happened so a good chance this is the cause.

try resetting the exchange server so it will bind with another GC, as it could be bound with the tombstoned server.

simply restart just to test to see fi it fixes for now.

the do the remove.

ill be back tomorrow so wount be ably to reply any more
0
 

Author Comment

by:rivey_210901
ID: 22665030
looks like that fixed it!!!!!!!!!!!   I'll test again in the morning and award points then!  Thanks
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22666786
which one? resetting of excahnge to bind to the other GC? or removing the bad DC?
0
 

Author Comment

by:rivey_210901
ID: 22668131
removing the dc fixed it.  i did a reboot for good measure overnight and problem is solved
0
 
LVL 11

Expert Comment

by:Bertling
ID: 22668163
GOOD! glad i can help
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now