Solved

DNS and Exchange

Posted on 2011-03-07
7
269 Views
Last Modified: 2012-08-13
Hi experts. I have a two part question about a problem I am trying to resolve.

Before the question, I'll provide the scenario.

I am using a vendor which is basically sending out promotion materials via our domain name with the exception that they are adding their own servers and then forwarding that to customers, etc.

For example, I have domain contoso.com. They are wanting to send email from vendor.contoso.com.  We house internal servers with contoso.com, but they want to send emails from @vendor.contoso.com. This is actually working to a certain extent because I have DNS entries on our external DNS servers which points to the "vendor" servers.

So, with this working as best I can describe, the piece that is not working is when a user is created on the vendor.contoso.com server as joe@vendor.contoso.com this address can't seem to email the domain of @contoso.com.

In fact, no user accounts setup with @vendor.contoso.com can email @contoso.com BUT those same users emailing from @vendor.contoso.com can email all other domains successfully i.e. joe@gmail.com

I am sure I am missing something easy, but can someone show a little pity and direct me to the water :)

Thanks all!
0
Comment
Question by:swcrook
7 Comments
 
LVL 5

Expert Comment

by:LLMorrisson
ID: 35057515
Not sure I understand the scenario; so are we talking about two different servers in different places? You have your server on site which is responsible for handling mail for contoso.com, and then another server on your vendor's site which is responsible for handling mail for vendor.contoso.com?

You say you "have NS entries on [your] external DNS servers which points to the "vendor" servers". Could you elaborate a little here? Exactly what do you have in DNS for that?

Sounds like you need to check what contoso.com resolves to at your *vendor* site, or from the vendor mailservers. In order to send email to you at contoso.com they will need to have the appropriate MX records pointing to the external IP addresses of the device you expect to receive the emails destined to you on that domain.

If they have set up the domain contoso.com and vendor.contoso.com on their own local/internal DNS servers they may just be trying to deliver the email somewhere internally on their own network.
0
 

Author Comment

by:swcrook
ID: 35057763
Sorry if I wasn't being clear, but you almost have the scenario.

We house @contoso.com and send email from this domain. Since the vendor we are working with wants to send lots and lots of emails to our customers, they wanted us to add NS entries to our external DNS servers that point to their servers for the domain vendor.contoso.com

For example:

vendor.contoso.com. 1800 IN NS ns1.vendor.com
vendor.contoso.com. 1800 IN NS ns2.vendor.com

The domain / subdomain:  vendor.contoso.com
Has an authotitaive nameserver at :  ns1.vendor.com
This nameserver will then resolve queries for this domain / subdomain.
0
 
LVL 3

Expert Comment

by:RussPitcher
ID: 35058004
I would imagine that Vendor would need to make sure that their server knows it is not authoritative for contoso.com.  If they are using Exchange 2007/2010 they should check the list of accepted domains in the hub transport section at the Org level. You could look at adding contoso.com as an accepted domain and create a send connector for traffic to that domain that directs the traffic straight at the appropriate mail server.
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 5

Accepted Solution

by:
LLMorrisson earned 500 total points
ID: 35058215
I'd also check it all looks correct just at the DNS level. From their mail server what do you get back if you run;

nslookup -type=mx contoso.com

Personally I probably wouldn't give them control over the entire subdomain vendor.contoso.com either. Rather, I'd just have the subzone set up on my own DNS and populate it will the relevant records as per their requirements. This ensures you maintain control over the zone.
0
 
LVL 5

Expert Comment

by:LLMorrisson
ID: 35058359
Btw, what happens to these messages so far, do you know?  Do they get any bounces?  Have they gone into the message tracking tool and searched for emails being sent to contoso.com? What can be found there?
0
 
LVL 3

Expert Comment

by:dtrance
ID: 35058617
So mail users @vender.contoso.com can send/receive email anywhere except to/from contoso.com?

What happens when they try?  Does it bounce?

Is the server handling mail for these domains the same?  Do you have a valid mx record for the sub domain?
0
 

Author Closing Comment

by:swcrook
ID: 35156650
This vendor is a marketing company that is up and coming. They don't have "control over the domain" because essentially they are just playing with a "fake" domain housed on their servers that they then use to send emails from.

This way, they are no in my AD, ever, adn they can send marketing emails as my company. I simply needed to trick AD and Exchange inot thinking that the server sending those particular emails would be routing to their severs.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Familiarize people with the process of retrieving data from SQL Server using an Access pass-thru query. Microsoft Access is a very powerful client/server development tool. One of the ways that you can retrieve data from a SQL Server is by using a pa…
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now