Solved

"Who sent that email?" search in Exchange 2010

Posted on 2010-11-29
8
1,504 Views
Last Modified: 2012-05-10
I have been asked by my boss to confidentially find out who sent an email to a specific email address.  He has given me the destination email address and the date and approximate time that the message was sent, withing a ½-hour window.

How do I search for that?  We have Exchange 2010.

Thanks,
Jono
0
Comment
Question by:Jono Martin
  • 4
  • 3
8 Comments
 
LVL 14

Expert Comment

by:athomsfere
Comment Utility
Was it sent from a group mailbox in your domain?

Do you have a copy of the message, or better yet the original email untouched / moved?
0
 
LVL 25

Accepted Solution

by:
Tony1044 earned 500 total points
Comment Utility
You can do it in the Exchange Management Console from within the tools, message tracking.

Or use the following Exchange Management Shell script:

Get-MessageTrackingLog -server abc -recipients abc@contoso.com -start "01/01/2010 00:01:00" -end "11/11/2010 23:59:00" | fl
0
 

Author Comment

by:Jono Martin
Comment Utility
Tony1044 - I get the following message in PowerShell when using the suggested command:

"The term 'Get-MessageTrackingLog' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again."

I do have SP1 installed (recently).  Is there something else I need to do to get these commands to work in PowerShell?

Thanks.
0
 
LVL 25

Expert Comment

by:Tony1044
Comment Utility
You need to run the exchange management shell, not plain old powershell.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:Jono Martin
Comment Utility
OK.  I have run the cmd and I have a couple of questions:
1. What does the "| fl" do?
2. Where can I find the results of this command?

Thanks again!
Jono
0
 

Author Closing Comment

by:Jono Martin
Comment Utility
Nevermind that last comment.  I see that it shows in the shell itself unless there are no results, which was the case.

Thanks for your help.
Jono
0
 

Author Comment

by:Jono Martin
Comment Utility
Actually, I'm still interested to know what the pipe command at the end means (" | fl ").

Thanks,
Jono
0
 
LVL 25

Expert Comment

by:Tony1044
Comment Utility
Format List. It gives more detail and can be used to filter with extra commands.
0

Featured Post

Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

Join & Write a Comment

Resolve DNS query failed errors for Exchange
Easy CSR creation in Exchange 2007,2010 and 2013
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now