Link to home
Start Free TrialLog in
Avatar of ellitech
ellitech

asked on

Creating a secondary SMTP email address in exhange - Recipient Policies

I am having an issue after creating an alias SMTP email address for a user at our company. The recipient policy being used is the 'Default Policy' with the required email addreses having been added. Our comapny has a main website that points to three other websites, one of the websites that it points to is www.acc-cameras.com. I created an email alias for the salesperson responsible for cameras. The email address uses the same format as all others, I added the domain acc-cameras.com. In the recipient policy it has '@acc-cameras.com' added in as well it has the 'This Exchange Organization is responsible for all mail delivery to this address'  has been checked. I spoke to the company that hosts our DNS records and they are telling me that everything is OK on their end.
I am completely stumped as to why this is NOT working as it should, PLEASE help as this is considered a HIGH priority to get this working correctly.

I am including a copy and paste from the MX Lookup Utility that I ran, please refer below:

ElliTech
Domain Mail Server/Exchanger for: accmanufacturing.ca
accmanufacturing.ca.	86400	IN	A	216.251.43.98
accmanufacturing.ca.	86400	IN	NS	ns.nucleus.com.
accmanufacturing.ca.	86400	IN	NS	ns1.nucleus.com.
 
ns.nucleus.com.        84009	IN	A	66.18.251.250
ns1.nucleus.com.	47592	IN	A	205.233.15.4
accmanufacturing.ca.	 86400	IN	MX	20mail2.accmanufacturing.ca.
accmanufacturing.ca.	  86400	IN	MX	10mail1.accmanufacturing.ca.
accmanufacturing.ca.	  86400	 IN	NS	ns.nucleus.com.
accmanufacturing.ca.	  86400	 IN	NS	ns1.nucleus.com.
mail1.accmanufacturing.ca. 86400           IN	A	68.179.2.169
mail2.accmanufacturing.ca. 86400           IN	A	142.179.154.39
ns.nucleus.com.	   84009           IN	A	66.18.251.250
ns1.nucleus.com.	   47592           IN	A	205.233.15.4
-----------------------------------------------------------------------
Domain Mail Server/Exchanger for: acc-cables.com
acc-cables.com.      86400	IN	A	66.18.192.127
acc-cables.com.      86400	IN	NS            ns1.nucleus.com.
acc-cables.com.      86400	IN	NS             ns.nucleus.com.
ns.nucleus.com        69611	IN	A	66.18.251.250
ns1.nucleus.com      69611	IN	A	205.233.15.4
acc-cables.com.      86400	IN	MX	20 smtp2.acc-cables.com.
acc-cables.com       86400	IN	MX	10 smtp.acc-cables.com.
acc-cables.com.      86400	IN	Nns1.nucleus.com.
acc-cables.com.      86400	IN	NS	ns.nucleus.com.
smtp.acc-cables.com.	86400	IN	A	68.179.2.169
smtp2.acc-cables.com.	86400	IN	A	142.179.154.39
ns.nucleus.com.                23390	IN	A	66.18.251.250
ns1.nucleus.com.              23390	IN	A	205.233.15.4
-----------------------------------------------------------------------
 
Domain Mail Server/Exchanger for: acc-cameras.com
acc-cameras.com.	10800	IN	A	216.251.43.98
acc-cameras.com.	10607	IN	NS	ns1.nucleus.com.
acc-cameras.com.	10607	IN	NS	ns.nucleus.com.
ns.nucleus.com.        83898	IN	A	66.18.251.250
ns1.nucleus.com.	47481	IN	A	205.233.15.
acc-cameras.com.	       10607	IN	MX	10 smtp.acc-cameras.com.
acc-cameras.com.	       10607	IN	NS	ns.nucleus.com.
acc-cameras.com.	       10607	IN	NS	ns1.nucleus.com.
smtp.acc-cameras.com     10607	IN	A	68.179.2.169
ns.nucleus.com.               83898	IN	A	66.18.251.250
ns1.nucleus.com.	       47481	IN	A	205.233.15.4

Open in new window

SOLUTION
Avatar of Rajith Enchiparambil
Rajith Enchiparambil
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of flyingsky
flyingsky

Looks like things are set up all right. Can you send a test email to that address in question and use your Exchange tracking center to see if your Exchange actually received the email?
Avatar of ellitech

ASKER

Hi Raijith,

Thank-you for taking the time to respond, I sent an email to an external address to test:

fromAcc Cameras <acccameras@acc-cameras.com>
to:mikeynetwrk05@gmail.com
cc;Michael Williams <mwilliams@cablesbyacc.com>
dateThu, May 14, 2009 at 8:55 AM
subjectTest from acccameras.com

hide details 8:55 AM (0 minutes ago) Reply

Test from acccameras.com

Everything looks fine, it sees it as coming from acc-cameras.com, but if I reply back it will fail...

Ellietch
As far as the IP, yes that is our STATIC public IP address...

ElliTech
Hi FlyingSky,

If I send a test email internally there is NO problem, it is only when the emails are sent from an external source that they will fail...

ElliTech
Here is the result of the REPLY email:

Mail Delivery Subsystem to me
show details 9:05 AM (0 minutes ago) Reply



This is an automatically generated Delivery Status Notification

Delivery to the following recipient failed permanently:

    acccameras@acc-cameras.com

Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550 No such domain at this location (acccameras@acc-cameras.com) (state 14).

  ----- Original message -----

MIME-Version: 1.0
Received: by 10.101.69.6 with SMTP id w6mr3241848ank.6.1242313511196; Thu, 14
       May 2009 08:05:11 -0700 (PDT)
In-Reply-To: <8DB91DFB8D028343BE181057100F9ADA9697E3@socket>
References: <8DB91DFB8D028343BE181057100F9ADA9697E3@socket>
Date: Thu, 14 May 2009 09:05:11 -0600
Message-ID: <28790fec0905140805q69953fb9t1e72c437c131cb71@mail.gmail.com>
Subject: Re: Test from acccameras.com
From: Michael <mikeynetwrk05@gmail.com>
To: Acc Cameras <acccameras@acc-cameras.com>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit


Test back...

On Thu, May 14, 2009 at 8:55 AM, Acc Cameras <acccameras@acc-cameras.com> wrote:
> Test from acccameras.com
When you send an email from outside to your @acc-cameras.com, do you get a bounced message or ndr back?
Create a test account in AD with mailbox and run the last test in Microsoft test site.

https://www.testexchangeconnectivity.com/

See what that flags.
Hope the following articles can help
1. Make sure you got the new recipient policy setup right
http://technet.microsoft.com/en-us/library/bb124859(EXCHG.65).aspx

2. how to trouble shoot
http://support.microsoft.com/kb/288807
I am attaching two screenshots, one for the reipient policy as well as one from the Message Tracking Center. I hope that this helps as I am completely stumped...

ElliTech
Message-Tracking-Center.JPG
Recipient-Policy.JPG
Restart the exchange services.
Hi Rajith,

I will get the following error:

Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550 No such domain at this location (acccameras@acc-cameras.com) (state 14).

It says that is a non-existent domain, does mean that there is an issue with the DNS not pointing correctly. At our company we have other email addresses that we use, this is the only one that is failing. The website www.acc-cameras.com was only recently added, that is why I am suspecting an issue wih DNS records perhaps...

ElliTech
Hi Rajith,

I re-started the exchange services yesterday as well as the SMTP service, no change. I will re-start them again just to make sure...

Ellitech
go to the following link and put in the new domain to see if you can get the correct information
http://www.dnscolos.com/free-dns-report.html

if you cannot, then something wrong with your DNS, either not setup correctly, or not updated.
if you can, then something is not working right on your Exchange box. follow my previouse post for trouble shooting
Create a test account in AD with mailbox and run the last test in Microsoft test site.

https://www.testexchangeconnectivity.com/

See what that flags. (Same post above as well)
Hi,

I re-started the exchange services again...

FlyingSky,
I am going to folow the link that you provided and see what I can come up with...thanks

ElliTech
I got the following:
------------

DNS report for acc-cameras.com
Category Status Test name Information
Parent Pass Parent nameservers acc-cameras.com Your NS records at the parent server l.gtld-servers.net are:

ns.nucleus.com [66.18.251.250]
ns1.nucleus.com [205.233.15.4]
 
Pass Nameservers for domain in DNS acc-cameras.com Your NS records at your nameservers are:

ns.nucleus.com [66.18.251.250]
ns1.nucleus.com [205.233.15.4]
 
MX Pass MX records for domain acc-cameras.com Your 1 MX records are:

10  smtp.acc-cameras.com  ip=68.179.2.169
 
Failed Mailserver connection test
HELO, MAIL FROM, RCPT TO, QUIT Connect to mailserver smtp.acc-cameras.com   FAILED (could be greylisting)
550 No such domain at this location (info@acc-cameras.com)  
Pass Public IPs test MX records are public IPs conform RFC 1918
Failed Mailserver greeting The server should have an A record which points to the mailserver for the hostname
which is presented in the greeting

smtp.acc-cameras.com
   220 mail.cablesbyacc.com ESMTP (5657a71dca765086e8bd85b32a3ea2b9)
 
Pass Open relay test for acc-cameras.com smtp.acc-cameras.com FAILED (VERY GOOD)
  220 mail.cablesbyacc.com ESMTP (5657a71dca765086e8bd85b32a3ea2b9) 250 mail.cablesbyacc.com Hello srv195086.webreus.nl [87.119.195.86], pleased to meet you
 250 Ok
 550 No such domain at this location (relaytest@relay.dnscolos.com)
 
 
Info Reverse DNS entries for MX records 169.2.179.68.in-addr.arpa  ->  static-68-179-2-169.ptr.terago.net.
 
SOA Pass SOA record for domain acc-cameras.com Your SOA record is:
Primary nameserver: ns.nucleus.com
Hostmaster E-mail address: abuse.nucleus.com
Serial #: 2009011202
Refresh: 7200
Retry: 3600
Expire: 604800
Default TTL: 10800
 
Info SOA Serial The SOA serial number is 2009011202. The preferred format is YYYYMMDDnn.
WWW Info record for www.acc-cameras.com www.acc-cameras.com A 216.251.43.98 TTL=[10800]
 
Pass WWW IP is public WWW has public IP conform RFC 1918
Pass CNAME record for acc-cameras.com No CNAME records exists
Info Webserver type (if available) for domain acc-cameras.com Found working Server: Apache  
-----------------

ElliTech
Is your firewall configured to allow port 25 traffic to your exchange?
Your Exchange box is not accepting emails sent to the new domain.
try configure a new recipient policy for that new domain.
I ran the test from the link provided:

 Testing Inbound SMTP Mail flow for domain acccameras@cablesbyacc.com
  Failed to test inbound SMTP mail flow.
 Test Steps
   Attempting to retrieve DNS MX records for domain cablesbyacc.com
  Successfully retrieved one or more MX records from DNS
 Additional Details
  MX Records Host mail.cablesbyacc.com, Preference 20, Host cablesbyacc.com, Preference 10  
 
 Testing Mail Exchanger cablesbyacc.com.
  This Mail Exchanger was tested successfully.
 Test Steps
   Attempting to Resolve the host name cablesbyacc.com in DNS.
  Host successfully Resolved
 Additional Details
  IP(s) returned: 68.179.2.169  
 
 Testing TCP Port 25 on host cablesbyacc.com to ensure it is listening/open.
  The port was opened successfully.
 Additional Details
  Banner Received: 220 mail.cablesbyacc.com ESMTP (5657a71dca765086e8bd85b32a3ea2b9)  
 
 Attempting to send test email message to acccameras@cablesbyacc.com using MX cablesbyacc.com.
  The test message was delivered successfully.
 
 Testing the MX cablesbyacc.com for open relay by trying to relay to user Admin@TestExchangeConnectivity.com
  Open Relay test passed. This mx is not an open relay
 Additional Details
  The open relay test message delivery failed (a good thing).
The exception detail is:
Exception Details:
Message: Mailbox unavailable. The server response was: No such domain at this location (Admin@TestExchangeConnectivity.com)
Type: System.Net.Mail.SmtpFailedRecipientException
Stack Trace:
at System.Net.Mail.SmtpTransport.SendMail(MailAddress sender, MailAddressCollection recipients, String deliveryNotify, SmtpFailedRecipientException& exception)
at System.Net.Mail.SmtpClient.Send(MailMessage message)
at Microsoft.Exchange.Tools.ExRca.Tests.SmtpOpenRelayTest.PerformTestReally()
 
 
 
 
FlyingSky,

In regards to the recipient policy, the 'Default Policy' is being used for all email addresses that we use as per the screenshot that I uploaded. As you can see the email address "@acc-cameras.com" is in there as well the checkbox has been checked...

ElliTech
I understand. as I said before, all the settings seems right, but not working right for you. That's why I suggest create another recipient policy.
OK..I will try to create a new recipient policy..strange how the default recipient policy is working for all other email addresses and just not for this one...

I ran the mail test again as well...

 Testing Inbound SMTP Mail flow for domain acccameras@acc-cameras.com
  Failed to test inbound SMTP mail flow.
 Test Steps
   Attempting to retrieve DNS MX records for domain acc-cameras.com
  Successfully retrieved one or more MX records from DNS
 Additional Details
  MX Records Host mail.acc-cameras.com, Preference 10  
 
 Testing Mail Exchanger mail.acc-cameras.com.
  One or more SMTP tests failed for this Mail Exchanger.
 Test Steps
   Attempting to Resolve the host name mail.acc-cameras.com in DNS.
  Host successfully Resolved
 Additional Details
  IP(s) returned: 68.179.2.169  
 
 Testing TCP Port 25 on host mail.acc-cameras.com to ensure it is listening/open.
  The port was opened successfully.
 Additional Details
  Banner Received: 220 mail.cablesbyacc.com ESMTP (5657a71dca765086e8bd85b32a3ea2b9)  
 
 Attempting to send test email message to acccameras@acc-cameras.com using MX mail.acc-cameras.com.
  The test message failed to be delivered.
 Additional Details
  Server returned status code 550 - Mailbox unavailable. The server response was: No such domain at this location (acccameras@acc-cameras.com)
Exception Details:
Message: Mailbox unavailable. The server response was: No such domain at this location (acccameras@acc-cameras.com)
Type: System.Net.Mail.SmtpFailedRecipientException
Stack Trace:
at System.Net.Mail.SmtpTransport.SendMail(MailAddress sender, MailAddressCollection recipients, String deliveryNotify, SmtpFailedRecipientException& exception)
at System.Net.Mail.SmtpClient.Send(MailMessage message)
at Microsoft.Exchange.Tools.ExRca.Tests.SmtpMessageTest.PerformTestReally()
 
 
Still the same result, non-existent domain...as soon as I create the recipient policy, I will apply it and see what happens and update the notes...

ElliTech
I am uploading screenshots of the NEW recipient policy that I created...

Please let me know what you think...

ElliTech
NEW-Recipient-Policy--1.JPG
NEW-Recipient-Policy--2.JPG
Has everyone given up on this already...PLEASE...I need to get this resolved ASAP...

Thanks in advance for staying on this, I depend on you guys to help...

ElliTech
Rajith,

YES, of course it is, ALL mail works except for email addresses using this domain @acc-cameras.com

"Rajith_Enchiparambil:Is your firewall configured to allow port 25 traffic to your exchange?"

ElliTech
Please refer to the below:

Test Steps
   Attempting to retrieve DNS MX records for domain cablesbyacc.com
  Successfully retrieved one or more MX records from DNS
 Additional Details
  MX Records Host cablesbyacc.com, Preference 10, Host mail.cablesbyacc.com, Preference 20  
 
 Testing Mail Exchanger cablesbyacc.com.
  This Mail Exchanger was tested successfully.
 Test Steps
   Attempting to Resolve the host name cablesbyacc.com in DNS.
  Host successfully Resolved
 Additional Details
  IP(s) returned: 68.179.2.169  
 
 Testing TCP Port 25 on host cablesbyacc.com to ensure it is listening/open.
  The port was opened successfully.
 Additional Details
  Banner Received: 220 mail.cablesbyacc.com ESMTP (5657a71dca765086e8bd85b32a3ea2b9)  
 
 Attempting to send test email message to acccameras@cablesbyacc.com using MX cablesbyacc.com.
  The test message was delivered successfully.
 
 Testing the MX cablesbyacc.com for open relay by trying to relay to user Admin@TestExchangeConnectivity.com
  Open Relay test passed. This mx is not an open relay
 Additional Details
 
 
 
 
Microsoft Exchange Server Remote Connectivity Analyzer Test MessageAdmin@TestExchangeConnectivity.com [Admin@TestExchangeConnectivity.com]
To:  Acc Cameras
Cc:  
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi FlyingSky,
Thank-you for continuing to respond back, it is greatly appreciated...thanks...

I don't have anything in the General Tab for this default policy that was created, does there need to be anything specific in there? I copied an existing recipient policy that we have that is working as far as I am aware of...

ElliTech
well, you need to set ldap filter, this tells which user(s) are applied.
in the general tab, click the "modify" button, then follow.
This is an automatically generated Delivery Status Notification

Delivery to the following recipient failed permanently:

    acccameras@acc-cameras.com

Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550 No such domain at this location (acccameras@acc-cameras.com) (state 14).
I added the user in question, still getting, the same error as above...

Ellitech
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
FlyingSky,

Just so that I understand exactly what you are saying, when you mention "well, you need to set ldap filter, this tells which user(s) are applied, in the general tab, click the "modify" button, then follow."

Just select the user or users in question, what if I want to apply to all users that are using "@acc-cameras.com" as a secondary email address? In the default recipient policy it has "(mailnickname=*)" as the only entry under 'Filter Rules'

Doesn't that apply it to all users? If so, how can I add that to the reipient policy that I created?

ElliTech
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I'll check out the spam filter that we have...hang on

ElliTech
First of all 'FlyingSky' I can't tell you haow relieved I am to get this figured out, it was something as simple as adding the domain to the allowable domains in the Barrucuda SPAM Filter. Thank-you so much for not giving up, I am in your debt. I was convinced that the problem was on the exchange server, not something simple like an entry missing on the SPAM filter...thank-you...

Rajith, thanks for trying, I aprreciate it, I am giving most of the points to FlyingSky as he kept engaged it was essential in resolving this...

ElliTech