Problems applying secondary SMTP domain policy and applying to domain users alias's on Exchange 2007 Enterprise Server SP1

Posted on 2009-06-30
Last Modified: 2012-05-07
Hi all.

We are running Exchange Enterprise 2007 server SP1 security update 8 and are preparing to change our domain name.

I want to be able to add a second SMTP domain for my Exchange server to listen for and have it assigned to my users.  

I have followed the steps found in this forum to create the new SMTP domain.

1.  Create an accepted domain and set the type to Authoritative, but not as Default.
     No problems
2.  Create E-mail Address Policy.  First tried  "All recipients types" .
     Default on conditions.  
     Added the accepted domain created earlier.
     Left the check box for E-mail address local part - Use Alias.
     Schedule Immediately.
          Watched as the process ran and appeared to apply to all users in my domain.
    Changed the priority to 2 and applied the policy.
          Watched as this process ran and it too appeared to apply to all of my users.

When I opened sample user properties -> E-Mail Addresses, I did not see the new accepted domain or email policy applied to the user's accounts.  Just the one from the "Default" policy.

When I run the Exchange shell command, Get-AcceptedDomain, I can see the newly created domain. I can see it as Authoritative and the default set to False.

Most users are set to automatically update e-mail addresses based on e-mail address policy.

I added the new domain to listen to in the "Default" policy and applied it to all of my users.  Still unable to see the new policy added to the user accounts.

I removed the new policy and accepted domain and retried the process with no luck.

I can manually add the SMTP to individual accounts with out problems (and email internally between the two different domains), but cannot get the policy to apply for all users in my domain at one time.

Any ideas?

Question by:TRFrye
  • 7
  • 5
LVL 27

Expert Comment

ID: 24746759
Users can only use ONE email policy at a time. You can create multiple email policies but the Mailboxes can only use ONE.

If you edit the Default to include your new domain, and then once you are ready to swap to the new domain you can edit again to set the new domain as the reply-to address.


Create the new policy as you have done and then set all the mailboxes to use the second policy instead of the Default.


Author Comment

ID: 24746963
Thanks for the super quick reply.

I had tried that in the past, but removed it when it didn't appear to work.  

I just  added the domain back to the "Default Policy" and re-applied it.  Still don't see it.  Shouldn't I see the domain added in the user's email addresses?

is there a refresh command that I need to run?  Do I need to remove the previous policy?  

I would like to be able to resolve both SMTP domains during the change over processes so as to not miss any email when I change the reply to domain.

How would I set the user's to use the second policy instead of the default?

LVL 27

Expert Comment

ID: 24747040
You may need to restart several services to apply this change immediantly. Probably the Information Store service or the Tranpsort service will do the trick, I'd need to test to see which for certain.


Author Comment

ID: 24747438

The only service that I have not restarted is the Exchange Active Directory Topology Service.  No updates to the user accounts.

Also, I only have the, not the  Would I need to have the alias added here?

Author Comment

ID: 24749007
I restarted all the Microsoft Exchange services, but it did not update the Email addresses SMTP box
LVL 27

Expert Comment

ID: 24757586
Hi TRFrye,

Sorry for the delay.

If you have more than 1 Email address policy (other than Default which is always lowest priority) that would affect the same set of users, the one that has the LOWEST NUMBER in priority column will take precedence.

So if you change the priority of the new EAP to 1 it should take effect immediantly.

Also see Update-EmailAddressPolicy -Identity [nameofEAP] to manually force this through (but should not be necessary)

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

LVL 27

Expert Comment

ID: 24757619
To clarify the EAP used by the mailbox is determined by the Conditions / Exceptions of your EAP's in EMC. If there is only 1 Default policy ALL will use this. If you create another EAP, and you have set the conditions and exceptions to catch your users, they will be using that EAP.

This way using EAP, you can have multiple EAP's to affect different groups of users based on different criteria. Such as an EAP for users of one company SMTP address space, 1 EAP for another company SMTP address space etc.


Author Comment

ID: 24762372

No problems.  Great information.  Out until Monday.

Just for clarification, I have three EAP's.  One is the default, obviously with the lowest.  Then I have current SMTP domain at level 1.  The third is the new SMTP domain and it is set to two.

In the default EAP, I have the active directy domain, @domain.local, the current SMTP domain,, a department that wanted to be a join our domain,, and funally I added the domain.  

For some reason I created 2 EAP with the setting of 1 for the current SMTP domain and one for the new SMTP domain with the level of 2, thinking that I needed to do this.  No conditions have been set for either of the other 2 EAP's.

This server was migrated from previous releases of Exchange (5.5, 2000. 2003) to the current 07 version.  There are even X400 connections there that I do not believe that I need, but haven't removed.  

Do you belive that the other EAP's should be removed and just add the new SMTP domain to the default EAP and change the reply from there?  That should allow the the current SMTP domain to remain as an "alias" right?

Again, thanks for your assistance.  Got to up the point value on this one.



Author Comment

ID: 24762397
I created the extra EAP's prior to adding the new SMTP domain to the default.  Could that be the reason that I am not able to see the new domain for the user email address profiles?

Also, should I use the or just the
LVL 27

Accepted Solution

shauncroucher earned 400 total points
ID: 24774344
It should be fine to just use and by default it will use the login name for the alias. There is a helpful wizard that will guide you through what Alias to apply (Exchange alias / Display name / firstname.lastname etc.

This guide should assist:

Once you know that the EAP is being applied to your users by using a secondary EAP as a test on a single account I would personally just remove ALL of your custom EAP's at that stage and amend the default to have the new SMTP address as the Reply to (it keeps things nice and simple). Then you may need to run the Update-EmailAddressPolicy command, but every time I have run this it will just apply to all recipients.

Check that your recipients are set to Automatically update via policy by following the article attached.

Let me know how you get on


Author Closing Comment

ID: 31598396

Thanks for all the expert information.  It was extremely helpful and worked like a champ.


Author Comment

ID: 24784445
I would like to clarify what I did to resolve this issue, with Shaun's assistance.

I removed the extra group policies that I thought that I had needed,, and  My default EAP contained the address for our domain.

I ran the wizard on the default policy and added the  I left the as my "Set as reply" so that I can start receiving Email from the domain also.

The wizard ran to completion without error and I was able to check random user accounts and have noted that the additional domain had been added.

Since Exchange will listen to only one domain at a time, the other two domains that I had created appeared to keep the default EAP from updating.  Removing those and re-applying the default appeared to resolve the issue.

Thanks Again!!!

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

939 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

4 Experts available now in Live!

Get 1:1 Help Now