Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Problems applying secondary SMTP domain policy and applying to domain users alias's on Exchange 2007 Enterprise Server SP1

Posted on 2009-06-30
Medium Priority
Last Modified: 2012-05-07
Hi all.

We are running Exchange Enterprise 2007 server SP1 security update 8 and are preparing to change our domain name.

I want to be able to add a second SMTP domain for my Exchange server to listen for and have it assigned to my users.  

I have followed the steps found in this forum to create the new SMTP domain.

1.  Create an accepted domain and set the type to Authoritative, but not as Default.
     No problems
2.  Create E-mail Address Policy.  First tried  "All recipients types" .
     Default on conditions.  
     Added the accepted domain created earlier.
     Left the check box for E-mail address local part - Use Alias.
     Schedule Immediately.
          Watched as the process ran and appeared to apply to all users in my domain.
    Changed the priority to 2 and applied the policy.
          Watched as this process ran and it too appeared to apply to all of my users.

When I opened sample user properties -> E-Mail Addresses, I did not see the new accepted domain or email policy applied to the user's accounts.  Just the one from the "Default" policy.

When I run the Exchange shell command, Get-AcceptedDomain, I can see the newly created domain. I can see it as Authoritative and the default set to False.

Most users are set to automatically update e-mail addresses based on e-mail address policy.

I added the new domain to listen to in the "Default" policy and applied it to all of my users.  Still unable to see the new policy added to the user accounts.

I removed the new policy and accepted domain and retried the process with no luck.

I can manually add the SMTP to individual accounts with out problems (and email internally between the two different domains), but cannot get the policy to apply for all users in my domain at one time.

Any ideas?

Question by:TRFrye
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 5
LVL 27

Expert Comment

ID: 24746759
Users can only use ONE email policy at a time. You can create multiple email policies but the Mailboxes can only use ONE.

If you edit the Default to include your new domain, and then once you are ready to swap to the new domain you can edit again to set the new domain as the reply-to address.


Create the new policy as you have done and then set all the mailboxes to use the second policy instead of the Default.


Author Comment

ID: 24746963
Thanks for the super quick reply.

I had tried that in the past, but removed it when it didn't appear to work.  

I just  added the domain back to the "Default Policy" and re-applied it.  Still don't see it.  Shouldn't I see the domain added in the user's email addresses?

is there a refresh command that I need to run?  Do I need to remove the previous policy?  

I would like to be able to resolve both SMTP domains during the change over processes so as to not miss any email when I change the reply to domain.

How would I set the user's to use the second policy instead of the default?

LVL 27

Expert Comment

ID: 24747040
You may need to restart several services to apply this change immediantly. Probably the Information Store service or the Tranpsort service will do the trick, I'd need to test to see which for certain.

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 24747438

The only service that I have not restarted is the Exchange Active Directory Topology Service.  No updates to the user accounts.

Also, I only have the, not the  Would I need to have the alias added here?

Author Comment

ID: 24749007
I restarted all the Microsoft Exchange services, but it did not update the Email addresses SMTP box
LVL 27

Expert Comment

ID: 24757586
Hi TRFrye,

Sorry for the delay.

If you have more than 1 Email address policy (other than Default which is always lowest priority) that would affect the same set of users, the one that has the LOWEST NUMBER in priority column will take precedence.

So if you change the priority of the new EAP to 1 it should take effect immediantly.

Also see Update-EmailAddressPolicy -Identity [nameofEAP] to manually force this through (but should not be necessary)

LVL 27

Expert Comment

ID: 24757619
To clarify the EAP used by the mailbox is determined by the Conditions / Exceptions of your EAP's in EMC. If there is only 1 Default policy ALL will use this. If you create another EAP, and you have set the conditions and exceptions to catch your users, they will be using that EAP.

This way using EAP, you can have multiple EAP's to affect different groups of users based on different criteria. Such as an EAP for users of one company SMTP address space, 1 EAP for another company SMTP address space etc.


Author Comment

ID: 24762372

No problems.  Great information.  Out until Monday.

Just for clarification, I have three EAP's.  One is the default, obviously with the lowest.  Then I have current SMTP domain at level 1.  The third is the new SMTP domain and it is set to two.

In the default EAP, I have the active directy domain, @domain.local, the current SMTP domain,, a department that wanted to be a join our domain,, and funally I added the domain.  

For some reason I created 2 EAP with the setting of 1 for the current SMTP domain and one for the new SMTP domain with the level of 2, thinking that I needed to do this.  No conditions have been set for either of the other 2 EAP's.

This server was migrated from previous releases of Exchange (5.5, 2000. 2003) to the current 07 version.  There are even X400 connections there that I do not believe that I need, but haven't removed.  

Do you belive that the other EAP's should be removed and just add the new SMTP domain to the default EAP and change the reply from there?  That should allow the the current SMTP domain to remain as an "alias" right?

Again, thanks for your assistance.  Got to up the point value on this one.



Author Comment

ID: 24762397
I created the extra EAP's prior to adding the new SMTP domain to the default.  Could that be the reason that I am not able to see the new domain for the user email address profiles?

Also, should I use the or just the
LVL 27

Accepted Solution

shauncroucher earned 1600 total points
ID: 24774344
It should be fine to just use and by default it will use the login name for the alias. There is a helpful wizard that will guide you through what Alias to apply (Exchange alias / Display name / firstname.lastname etc.

This guide should assist:

Once you know that the EAP is being applied to your users by using a secondary EAP as a test on a single account I would personally just remove ALL of your custom EAP's at that stage and amend the default to have the new SMTP address as the Reply to (it keeps things nice and simple). Then you may need to run the Update-EmailAddressPolicy command, but every time I have run this it will just apply to all recipients.

Check that your recipients are set to Automatically update via policy by following the article attached.

Let me know how you get on


Author Closing Comment

ID: 31598396

Thanks for all the expert information.  It was extremely helpful and worked like a champ.


Author Comment

ID: 24784445
I would like to clarify what I did to resolve this issue, with Shaun's assistance.

I removed the extra group policies that I thought that I had needed,, and  My default EAP contained the address for our domain.

I ran the wizard on the default policy and added the  I left the as my "Set as reply" so that I can start receiving Email from the domain also.

The wizard ran to completion without error and I was able to check random user accounts and have noted that the additional domain had been added.

Since Exchange will listen to only one domain at a time, the other two domains that I had created appeared to keep the default EAP from updating.  Removing those and re-applying the default appeared to resolve the issue.

Thanks Again!!!

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question