Solved

Exchnage 2003 Mail Relay

Posted on 2011-02-24
7
657 Views
Last Modified: 2012-05-11
I manage an Exchange 2003 server with all service packs and security fixes applied.  I have triple checked this server so that it does not relay.  I even used the following article to confirm its setup not to relay:

http://www.servolutions.com/support/config_exchange_2003.htm#section3

Everything checks out.  However, when I run an online relay test on http://www.test-smtp.com/, its states my server is a relay.  This site conducts 28 tests, and on Test 17 it states Host is an open relay!

I ran another online test on this site:  http://www.antispam-ufrj.pads.ufrj.br/test-relay.html
and it stated "Relay test result
Ops!!! Host appeared to accept a message relay, but it may or not may a positive open relay. I need procced a complete test, sending a test message to probe it. This anonymous user test did not send a test message. "

I manage several Exchange 2003 servers with an identical smpt connector setup and do not have a relay problem.  

In the app event viewer, I saw the following Event ID 7010 (MSExchangeTransport) message:

Event Type:      Error
Event Source:      MSExchangeTransport
Event Category:      SMTP Protocol
Event ID:      7010
Date:            2/24/2011
Time:            3:20:21 PM
User:            N/A
Computer:      APOLLO
Description:
This is an SMTP protocol log for virtual server ID 2, connection #8. The client at "146.164.48.5" sent a "rcpt" command, and the SMTP server responded with "550 5.7.1 Unable to relay for relaytest%antispam-ufrj.pads.ufrj.br@[216.54.12.59]  ". The full command sent was "rcpt TO:<relaytest%antispam-ufrj.pads.ufrj.br@[216.54.12.59]>".  This will probably cause the connection to fail.

I am a bit confused in that this server could a relay, but I've done everything possible to ensure its not.  Any ideas as to what is going on?
0
Comment
Question by:cmp119
  • 3
  • 2
  • 2
7 Comments
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 34974114
I'm not familiar with the sites you used for your test.  Try MXToolbox - it's very simple:

www.mxtoolbox.com/diagnostic.aspx

The 7010 error message is a very good indicator that relays are not being allowed.

Just curious - where did you come up with the server name "Apollo"? Is that your actual server name?
0
 
LVL 42

Expert Comment

by:Amit
ID: 34974177
This seems to be Permissions problem.  It looks that the sender is not allowed to email this account or an anonymous user is trying to send mail to a DL.

Follow below steps:

Check SMTP Virtual Server Access Tab.  

Check : Allow computers which successfully authenticate to relay

Lastly, check at user end, might be user created email address that does not match your exchange server system policy.
0
 
LVL 42

Expert Comment

by:Amit
ID: 34974190
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:cmp119
ID: 34978851
hypercat - I also tried mxtoolbox, and the results were and still are favorable.  Everything gave a green light with the exception of a Warning - Reverse DNS does not match smtp banner.  That's no big deal, and I am not concerned with that warning.  

I usually name my servers after Greek Gods, and I usually name the Exchange Server Apollo.
0
 

Author Comment

by:cmp119
ID: 34978908
amitkulshrestha, The setting "Allow all computers which successfully authenicate to relay, regardless of the list above" setting is checked.  The Event ID 7010 message displayed abovdisplayed on the exchange server when I ran the online smtp relay tests.  Each individual relay test were denied relay access, but then towards the end the test revealed it was an open relay.  So I included the 7010 event id of the attempt to relay by that particular test, and I believe it could not relay based on that message.  I just fiind it confusing some online sites indicate this exchange server is a relay and others not.  I manage other exchange servers with identical default smpt protocal settings and all sites indicate they are not relays with the exception of this mail server.  I hope this explanation makes sense.  
0
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 500 total points
ID: 34980596
I think you are all set, cmp119.  The rDNS warning will not cause any issues in the real-world, as you know, as long as there IS an rDNS record. Although to make everything completely and utterly correct, you should have the ISP change the PTR record to match your public mail server name (the one that it is advertising on the banner) if possible.

(ASIDE) The reason I asked about the server name is because I do a similar thing. I believe even techies (maybe especially techies) need a creative outlet sometimes too, and it just irritates me when someone names all their servers "Server1" Server2" etc., could you be MORE BORING!  It seemed a weird coincidence to me, though, that it so happens I have a client site where I use Apollo as the email server name too (along with Circe, Atlas, Mercury, etc., for the other servers).
0
 

Author Comment

by:cmp119
ID: 34999994
hpercat - I agree in that my mail server is not truly a relay.  The SMTP banner should be updated, and I might do that in the future.  Thank you
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data‚Ķ
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question