Solved

Exchange Unable to receive emails from Some Domains.

Posted on 2009-07-07
28
476 Views
Last Modified: 2013-11-30
Help!
We are unable to receive emails from some domains like aol(sometimes), Gmail, and other domains.
But we are able to sent emails to the domains,  the Reports from  pingability.com mxtoolbox.copm and dnsstuff.com show all the DNS Settings OK.

I'm using wireshark and I can see there's a connection timeout , I increased the smtp connection timeout but still having the issue...

Exchange 2003 spack 2 runing on windows 2003 network.
I have the Exchange/SPAM feature disable.

Thanks!
aol.txt
0
Comment
Question by:abarona
  • 14
  • 13
28 Comments
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 400 total points
ID: 24799535
Try changing your mail server name internally as it is currently set to be a different server to the one advertised:
mail.g-g-h.com claims to be non-existent host GULF-SRV30.FL.G-G-H.COM: <br /> 220 GULF-SRV30.FL.G-G-H.COM Microsoft ESMTP MAIL Service, Version: 6.0.3790.3959 ready at Tue, 7 Jul 2009 19:34:03 -0400 <br />
Open Up ESM, Expand Servers, Expand YourServer, Expand Protocols, Expand SMTP, Select the default SMTP Virtual Server.  Right click SMTP Virtual server and choose properties.  On the  Delivery Tab, click on the Advanced button and make sure the FQDN name is shown as mail.g-g-h.com.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24799546
Your RDNS pointer points back to mail.g-g-h.com so if you change your FQDN in SMTP Virtual Server, this should resolve properly and the likes of AOL should get through to you.
0
 

Author Comment

by:abarona
ID: 24799633
alanhardisty

I just did the changes, and restarted the services will try and let you know.
0
 

Author Comment

by:abarona
ID: 24807360
After i did all the changes I still have the same issue attached is the new error message.
I have the same problem with gmail, aol and other private domains.
I can't find a solution... \\

Thanks for any help...

Al
Aolerror.txt
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24807442
What firewall have you got installed?
0
 

Author Comment

by:abarona
ID: 24807586
Hotbrick 1200 being used for almost 4 years without problems, I noticed in the firewall tcp Connection Dropped in port (25) SMTP last week, but now i don't see it anymore.
0
 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 400 total points
ID: 24807733
Have you checked for firmware updates for the Hotbrick?
0
 

Author Comment

by:abarona
ID: 24807817
We  had a Barracuda Spamarrest box and we removed it, believing it was causing the timeout.
But the problem remained so after that we set the Firewall to invisible allowing all trafic but the problem still there, it has the latest firmware.
We check the Domain name for blacklists and we are ok, the ip is fine too...
We are pretty sure is the server itself I was hoping your suggestion willsolve the problem since it may sense, it was using the FQDN from the machine Itsel and not the MX Record.
But they are loosing sensitive and timely emails and they want my head now....
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24807855
Whilst at it - it can't hurt to check for updates to your server - always good to rule out your end having problems that a patch or service pack has already fixed.
Windowsupdate is always a good place to look.
Do you have a spare firewall you can install temporarily to rule out the existing one?  Might be worth buying a cheapo one and configuring it as your existing one is, testing AOL mail and then replacing the Hotbrick.
0
 

Author Comment

by:abarona
ID: 24808014
I did it , with a Linksys Cisco firewall  first  with the right ports open, same scenario, after I decided to bring down the firewall (crazy thing ahh), but still the same issue.

I going to wait for another 24 Hours since I  make the modificationa last night, my last resource is install maildemon Server and  test the configuration it maybe an Exchange rule agains AOL or Gmail Sync...

I'm receiving tons of Junk Emails since my spamarrrest is down now, so im pretty sure is some kind of sync between the SMTP servers.... I ran wiredshark on th exchange server and I can see a connection drop between AOL and the SMTP, the smtp timeout is maxed out in the Exchange box.
0
 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 400 total points
ID: 24808104
Have you changed the firewall and still no difference?
There are tons of other web posting with AOL issues receiving mail with the same errors you are getting - no consolation, but you are not alone.  No solutions yet though :-(
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24808248
Are you performing reverse DNS lookups on your SMTP Connector?
If you are, please disable it and test again.
It is set where on the same screen that you set the FQDN of the mail server under default SMTP Virtual server.
 
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24808251
Sorry - the above should read:
Are you performing reverse DNS lookups on your SMTP Virtual Server?
If you are, please disable it and test again.
It is set where on the same screen that you set the FQDN of the mail server under default SMTP Virtual server.
 
0
 

Author Comment

by:abarona
ID: 24808373
It's disable (uncheck)
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24808525
Are you using Microsoft SPF filtering?
Check the settings under Message Delivery properties for Intelligent Message Filtering.  Are you rejecting messages that fail?  If you are, please set to No Action and test again.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24808556
Also disable Sender ID Filtering if it is set to reject in the Message Delivery settings.
0
 

Author Comment

by:abarona
ID: 24808631
those are the settings right now.
IMF is set to no action.
Sender ID filtering is set to Accept for further antispam filtering
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24808699
Well that really only leaves a problem with AOL / Gmail.
0
 

Author Comment

by:abarona
ID: 24808769
I'm hopping by tomorrow it will be fine, it may be a propagation issue due to the wrong name in the FQDN, but makes not sense since with all the other domains is just fine..
I also increase the number of hops to double thinking it maybe a slow network connection, and 30 the number of messages per connection.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24808793
I agree that waiting 24 hours would be a good idea.  If it fails after this time, then I am out of ideas!
0
 

Author Comment

by:abarona
ID: 24813254
I still have the same problems,
Deferred: Connection timed out with mail.g-g-h.com.
Message could not be delivered for 3 hours
I'm going to ask our ISP  to check out the line, I notice sometime we have alot of Hops doing a trace to AOL, not sure it that may cause the timeout connection.
Can you email me a backupexec@g-g-h.com and see what response you have  ping/tracert to mail.g-g-h.com

Thanks!
aolerror2.txt
0
 

Author Comment

by:abarona
ID: 24839010
We are receiving emails from AOL, not sure if all of them but we believe we found the problem.
Our ISP gave us a set of IP's and one of the Ip's in the Cisco Box was Blacklisted with SORBS.
Still an issue with Gmail. I'll have to wait until the Blacklists remove the IP.   and verify with the  other domains.


0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24839067
Ah - the old blacklisting problem!
Glad you are getting to the bottom of the problem.  If only I'd asked if you had multiple IP's!!!
0
 

Author Comment

by:abarona
ID: 24852652
I verified with AOL but our IP was OK with them so the blacklists wasn't the problem.
I'm attaching the TXT file of a returned email from AOL  I notice error status 4.4.7, the max number of receipients to 100 and the number of connections to 20 (default).
I tested the IP using MXtoobox.com and it was ok, any other site to test the IP againts blacklist..?

A week today and still with the same problem.......

Thanks for any help
aolerror3.txt
0
 
LVL 27

Assisted Solution

by:shauncroucher
shauncroucher earned 100 total points
ID: 24852716
Have you reviewed this article:

http://www.experts-exchange.com/Networking/Email_Groupware/Sendmail/Q_21876883.html

They had the same SMTP error, and they updated their firewall to fix the problem. You are using a hotbrick 1200. I know this has been working for 4yrs without a problem, but it may still be the culprit nonetheless.

Can you possible bypass or replace this just as a temporary test?

Shaun
0
 

Author Comment

by:abarona
ID: 24852944

I replaced it before with an spare firewall with the same result.
Will do it again with a small Linksys firewall and leave it on...

Thanks!





0
 

Author Comment

by:abarona
ID: 24913853
I'm sorry for not getting back sooner but I finally nailed the problem.
The Problem was a combination:
1. IP was Balcklisted
2. Firewall was timing out resolving the DNS server (running 2003.) I found some threats about old Firewalls and the new DNS broadcasting mode in 2003.
After 4 days the blacklisted Ip worked fine with Aol, but as soon I change the Firewall to one Linksys/Cisco the problem with Gmail and the other Domains was resolved.
The Barracuda spamarrest is back online again and all the email are OK and fine...

Thanks to all for the Ideas and support, Hope this threat and resolutions help other with the same problem!

0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24913955
Great news - you may as well close down the question as you see fit.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now