?
Solved

"Who sent that email?" search in Exchange 2010

Posted on 2010-11-29
8
Medium Priority
?
1,580 Views
Last Modified: 2012-05-10
I have been asked by my boss to confidentially find out who sent an email to a specific email address.  He has given me the destination email address and the date and approximate time that the message was sent, withing a ½-hour window.

How do I search for that?  We have Exchange 2010.

Thanks,
Jono
0
Comment
Question by:Jono Martin
  • 4
  • 3
8 Comments
 
LVL 14

Expert Comment

by:athomsfere
ID: 34231492
Was it sent from a group mailbox in your domain?

Do you have a copy of the message, or better yet the original email untouched / moved?
0
 
LVL 26

Accepted Solution

by:
Tony J earned 2000 total points
ID: 34231535
You can do it in the Exchange Management Console from within the tools, message tracking.

Or use the following Exchange Management Shell script:

Get-MessageTrackingLog -server abc -recipients abc@contoso.com -start "01/01/2010 00:01:00" -end "11/11/2010 23:59:00" | fl
0
 

Author Comment

by:Jono Martin
ID: 34233119
Tony1044 - I get the following message in PowerShell when using the suggested command:

"The term 'Get-MessageTrackingLog' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again."

I do have SP1 installed (recently).  Is there something else I need to do to get these commands to work in PowerShell?

Thanks.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 26

Expert Comment

by:Tony J
ID: 34233164
You need to run the exchange management shell, not plain old powershell.
0
 

Author Comment

by:Jono Martin
ID: 34234307
OK.  I have run the cmd and I have a couple of questions:
1. What does the "| fl" do?
2. Where can I find the results of this command?

Thanks again!
Jono
0
 

Author Closing Comment

by:Jono Martin
ID: 34234339
Nevermind that last comment.  I see that it shows in the shell itself unless there are no results, which was the case.

Thanks for your help.
Jono
0
 

Author Comment

by:Jono Martin
ID: 34234404
Actually, I'm still interested to know what the pipe command at the end means (" | fl ").

Thanks,
Jono
0
 
LVL 26

Expert Comment

by:Tony J
ID: 34236989
Format List. It gives more detail and can be used to filter with extra commands.
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Steps to fix “Unable to mount database. (hr=0x80004005, ec=1108)”.
There can be many situations demanding the conversion of Outlook OST files to PST format and as such, there is no shortage of automated tools to perform this conversion. However, what makes Stellar OST to PST converter stand above the rest? Let us e…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
Suggested Courses

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question