Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

DNS and Exchange

Posted on 2011-03-07
7
Medium Priority
?
279 Views
Last Modified: 2012-08-13
Hi experts. I have a two part question about a problem I am trying to resolve.

Before the question, I'll provide the scenario.

I am using a vendor which is basically sending out promotion materials via our domain name with the exception that they are adding their own servers and then forwarding that to customers, etc.

For example, I have domain contoso.com. They are wanting to send email from vendor.contoso.com.  We house internal servers with contoso.com, but they want to send emails from @vendor.contoso.com. This is actually working to a certain extent because I have DNS entries on our external DNS servers which points to the "vendor" servers.

So, with this working as best I can describe, the piece that is not working is when a user is created on the vendor.contoso.com server as joe@vendor.contoso.com this address can't seem to email the domain of @contoso.com.

In fact, no user accounts setup with @vendor.contoso.com can email @contoso.com BUT those same users emailing from @vendor.contoso.com can email all other domains successfully i.e. joe@gmail.com

I am sure I am missing something easy, but can someone show a little pity and direct me to the water :)

Thanks all!
0
Comment
Question by:swcrook
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 5

Expert Comment

by:LLMorrisson
ID: 35057515
Not sure I understand the scenario; so are we talking about two different servers in different places? You have your server on site which is responsible for handling mail for contoso.com, and then another server on your vendor's site which is responsible for handling mail for vendor.contoso.com?

You say you "have NS entries on [your] external DNS servers which points to the "vendor" servers". Could you elaborate a little here? Exactly what do you have in DNS for that?

Sounds like you need to check what contoso.com resolves to at your *vendor* site, or from the vendor mailservers. In order to send email to you at contoso.com they will need to have the appropriate MX records pointing to the external IP addresses of the device you expect to receive the emails destined to you on that domain.

If they have set up the domain contoso.com and vendor.contoso.com on their own local/internal DNS servers they may just be trying to deliver the email somewhere internally on their own network.
0
 

Author Comment

by:swcrook
ID: 35057763
Sorry if I wasn't being clear, but you almost have the scenario.

We house @contoso.com and send email from this domain. Since the vendor we are working with wants to send lots and lots of emails to our customers, they wanted us to add NS entries to our external DNS servers that point to their servers for the domain vendor.contoso.com

For example:

vendor.contoso.com. 1800 IN NS ns1.vendor.com
vendor.contoso.com. 1800 IN NS ns2.vendor.com

The domain / subdomain:  vendor.contoso.com
Has an authotitaive nameserver at :  ns1.vendor.com
This nameserver will then resolve queries for this domain / subdomain.
0
 
LVL 3

Expert Comment

by:RussPitcher
ID: 35058004
I would imagine that Vendor would need to make sure that their server knows it is not authoritative for contoso.com.  If they are using Exchange 2007/2010 they should check the list of accepted domains in the hub transport section at the Org level. You could look at adding contoso.com as an accepted domain and create a send connector for traffic to that domain that directs the traffic straight at the appropriate mail server.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 5

Accepted Solution

by:
LLMorrisson earned 2000 total points
ID: 35058215
I'd also check it all looks correct just at the DNS level. From their mail server what do you get back if you run;

nslookup -type=mx contoso.com

Personally I probably wouldn't give them control over the entire subdomain vendor.contoso.com either. Rather, I'd just have the subzone set up on my own DNS and populate it will the relevant records as per their requirements. This ensures you maintain control over the zone.
0
 
LVL 5

Expert Comment

by:LLMorrisson
ID: 35058359
Btw, what happens to these messages so far, do you know?  Do they get any bounces?  Have they gone into the message tracking tool and searched for emails being sent to contoso.com? What can be found there?
0
 
LVL 3

Expert Comment

by:dtrance
ID: 35058617
So mail users @vender.contoso.com can send/receive email anywhere except to/from contoso.com?

What happens when they try?  Does it bounce?

Is the server handling mail for these domains the same?  Do you have a valid mx record for the sub domain?
0
 

Author Closing Comment

by:swcrook
ID: 35156650
This vendor is a marketing company that is up and coming. They don't have "control over the domain" because essentially they are just playing with a "fake" domain housed on their servers that they then use to send emails from.

This way, they are no in my AD, ever, adn they can send marketing emails as my company. I simply needed to trick AD and Exchange inot thinking that the server sending those particular emails would be routing to their severs.
0

Featured Post

Moving data to the cloud? Find out if you’re ready

Before moving to the cloud, it is important to carefully define your db needs, plan for the migration & understand prod. environment. This wp explains how to define what you need from a cloud provider, plan for the migration & what putting a cloud solution into practice entails.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question