Solved

DNS and Exchange

Posted on 2011-03-07
7
274 Views
Last Modified: 2012-08-13
Hi experts. I have a two part question about a problem I am trying to resolve.

Before the question, I'll provide the scenario.

I am using a vendor which is basically sending out promotion materials via our domain name with the exception that they are adding their own servers and then forwarding that to customers, etc.

For example, I have domain contoso.com. They are wanting to send email from vendor.contoso.com.  We house internal servers with contoso.com, but they want to send emails from @vendor.contoso.com. This is actually working to a certain extent because I have DNS entries on our external DNS servers which points to the "vendor" servers.

So, with this working as best I can describe, the piece that is not working is when a user is created on the vendor.contoso.com server as joe@vendor.contoso.com this address can't seem to email the domain of @contoso.com.

In fact, no user accounts setup with @vendor.contoso.com can email @contoso.com BUT those same users emailing from @vendor.contoso.com can email all other domains successfully i.e. joe@gmail.com

I am sure I am missing something easy, but can someone show a little pity and direct me to the water :)

Thanks all!
0
Comment
Question by:swcrook
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 5

Expert Comment

by:LLMorrisson
ID: 35057515
Not sure I understand the scenario; so are we talking about two different servers in different places? You have your server on site which is responsible for handling mail for contoso.com, and then another server on your vendor's site which is responsible for handling mail for vendor.contoso.com?

You say you "have NS entries on [your] external DNS servers which points to the "vendor" servers". Could you elaborate a little here? Exactly what do you have in DNS for that?

Sounds like you need to check what contoso.com resolves to at your *vendor* site, or from the vendor mailservers. In order to send email to you at contoso.com they will need to have the appropriate MX records pointing to the external IP addresses of the device you expect to receive the emails destined to you on that domain.

If they have set up the domain contoso.com and vendor.contoso.com on their own local/internal DNS servers they may just be trying to deliver the email somewhere internally on their own network.
0
 

Author Comment

by:swcrook
ID: 35057763
Sorry if I wasn't being clear, but you almost have the scenario.

We house @contoso.com and send email from this domain. Since the vendor we are working with wants to send lots and lots of emails to our customers, they wanted us to add NS entries to our external DNS servers that point to their servers for the domain vendor.contoso.com

For example:

vendor.contoso.com. 1800 IN NS ns1.vendor.com
vendor.contoso.com. 1800 IN NS ns2.vendor.com

The domain / subdomain:  vendor.contoso.com
Has an authotitaive nameserver at :  ns1.vendor.com
This nameserver will then resolve queries for this domain / subdomain.
0
 
LVL 3

Expert Comment

by:RussPitcher
ID: 35058004
I would imagine that Vendor would need to make sure that their server knows it is not authoritative for contoso.com.  If they are using Exchange 2007/2010 they should check the list of accepted domains in the hub transport section at the Org level. You could look at adding contoso.com as an accepted domain and create a send connector for traffic to that domain that directs the traffic straight at the appropriate mail server.
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 5

Accepted Solution

by:
LLMorrisson earned 500 total points
ID: 35058215
I'd also check it all looks correct just at the DNS level. From their mail server what do you get back if you run;

nslookup -type=mx contoso.com

Personally I probably wouldn't give them control over the entire subdomain vendor.contoso.com either. Rather, I'd just have the subzone set up on my own DNS and populate it will the relevant records as per their requirements. This ensures you maintain control over the zone.
0
 
LVL 5

Expert Comment

by:LLMorrisson
ID: 35058359
Btw, what happens to these messages so far, do you know?  Do they get any bounces?  Have they gone into the message tracking tool and searched for emails being sent to contoso.com? What can be found there?
0
 
LVL 3

Expert Comment

by:dtrance
ID: 35058617
So mail users @vender.contoso.com can send/receive email anywhere except to/from contoso.com?

What happens when they try?  Does it bounce?

Is the server handling mail for these domains the same?  Do you have a valid mx record for the sub domain?
0
 

Author Closing Comment

by:swcrook
ID: 35156650
This vendor is a marketing company that is up and coming. They don't have "control over the domain" because essentially they are just playing with a "fake" domain housed on their servers that they then use to send emails from.

This way, they are no in my AD, ever, adn they can send marketing emails as my company. I simply needed to trick AD and Exchange inot thinking that the server sending those particular emails would be routing to their severs.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange server Error 3 42
192.168... network can't ping 18 36
Office 365 Spam 3 33
email archiving on exchange 2010 16 29
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question