Exchange
--
Questions
--
Followers
Top Experts
Response: 250 2.6.0 Â <EFEE469B8E084445AB80E36D2
Response code: 250
Response parameter: 2.6.0 Â <EFEE469B8E084445AB80E36D2
Command: QUIT\r\n
[ACK]
Response: 221 2.0.0 mail.kilmercpa.com Service closing transmission channel\r\n
Response code: 221
Response parameter: 2.0.0 mail.kilmercpa.com Service closing transmission channel
[FIN, ACK]
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
This sounds to me like a problem in pure hosts mx config, have you contacted them?
Cheers
Liquid
- starting at the beginning, you seem to have name servers problems... at the registrar, you have you name server listed as:
ns1.windowsww.com. [38.113.1.38] [TTL=172800] [US]
ns2.windowsww.com. [38.113.1.39] [TTL=172800] [US]
but in you DNS, you have:
ns1.yourhostingaccount.com
ns2.yourhostingaccount.com
That can create all sorts of issues... you need to make sure the nameservers listed at the registrar are the nameservers that are actually in you DNS as NS records...
- you do have the issue with not sending the hostname in your greeting - that can be a problem and should be corrected... so you hav any SPAM or mail gateway in front of you primary email server?
- lastly, you should set up an SPF record for your domain...
Again, though, start at the beginning and get your name servers correct either by changing at the registrar, or correcting the DNS NS records... then test everything again and see what happens...






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
So if, in your example, greenwayeng.com is using ns1/ns2.yourhostingaccount
This sometimes happens when you change DNS providers or registrars and the info doesn't get correctly updated. There can be instances (rare) where odd configurations can be valid, but you would have already said "their supposed to be that way".... (you can still say that if you have some complication DNS set up)....
What is also odd, is that if I do an NSLOOKUP on your domain at the windowsww.com server, I get an 'authoritative' answer - which means they have the records for your domain and are not looking them up elsewhere.... but when I do that same lookup at yourhostingaccount.com, I get the same 'authoritative' answer... and all the records do look the same, including the NS records at BOTH pointing to yourhostingaccount.com....
Maybe those nameservers are at the same hsoting company (they do have different IP addresses), but in any event, there should be a match between registrar and DNS, so figure out which are the correct nameservers, and change them either at the registrar or on the DNS servers...
This alone, however, does not explain the issue with your mail, as you said, the  mail IS coming in - you have a capture of the SMTP - so as I asked, do you have any SPAM, or other gateway in front of the Exchange server... when I try to manuall telnet in on port 25 to your mail server (mail.greenwayeng.com), I cannot even connect, so I'm being blocked even before that server....
Right now I have Telnet blocked, but I can open it up so you can come in.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
but this is good info... the WatchGuard is probably where things are getting messed up... is the WatchGuard acting as a gateway for email? Whose IP address actually is at mail.greenwayeng.com? Is that NAT to the Exchange server, or is the WatchGuard running SMTP, checking the mail (even just the header), then forwarding to Exchange? I you telnet to the internal IP address of your Exchange server on port 25, do you get the 'correct' SMTP response?
The IP address 64.181.96.242 is my public IP address and is NAT'd by the Firebox to my exchange server. The firebox is running the SMTP proxy and Spamscreen.
If I telnet to the servers internal IP on port 25 the server answers with ready and I can do the regular commands.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
From what I know so far, it seems like you should have entries such as:
greenwayeng.com   A   38.113.20.15   -> most people want their TLD to go to their website, even if you don't type www.
greenwayeng.com   NS   ns1.<whatever your correct name servers are>
greenwayeng.com   NS   ns2.<whatever your correct name servers are>
greenwayeng.com   MX   10   mail.greenwayeng.com   -> send mail to 'mail.greenwayeng.com'
mail.greenwayeng.com   A   64.181.96.242   -> NAT of Exchange (on Firebox)
www.greenwayeng.com  A   38.113.20.15   -> IP address of web site
I am now able to telnet to mail.greenwayeng.com on port 25, and I do see the generic mail greeting. If you see the correct Exchange greeting when you connect internally, then I am missing some information. What version/model is the firebox?
Does this look familiar: http://www.watchguard.com/help/docs/fireware/10/en-us/content/en-us/proxies/smtp/proxy_smtp_gen_settings_f.html ? If so, look at the section under "Hide Email Server" and check "Server Replied" and "Rewrite Banner Domain", and put 'mail.greenwayeng.com' in there. Also check "Rewrite HELO Domain" and put 'mail.greenwayeng.com' in there...
220 mail.greenwayeng.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at  Fri, 15 Apr 2011 14:46:23 -0400
I am using an older Firebox III 1000, the menus look quite a bit different than the link. I do see the "SMTP Service Ready" as the welcome message under the SMTP Proxy. I dont see any options to change it though. I am using Policy Manager 7.5.0-B2561

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
"but still it is my firebox answering and not the exchange server..." - I'm not familiar with that exact model, but the firebox acts as an SMTP... somewhere do you have a configuration for "Incoming SMTP Proxy"? That's the configuration for the Firebox to intercept the SMTP message, examine it for whatever, then forward to the Exchange server... so the mail goes:
Internet->Firebox->Exchang
What version of software is running on the Firebox? The Firebox may also be doing some sort of user verification to Exchange and it may be failing...
You originally said "I can't see his email in the exchange logs but if I use wireshark on the exchange server I can see it come in"... you have WireShark running on the Exchange server and you see it come in where? on the local IP of the Exchange server? What version of Exchange is this? Is that capture from Internet->Firebox or Firebox->Exchange?
On the capture, I see "gw8.greenwayeng.com" - what is "gw8"?






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Wireshark was capturing anything coming into the NIC, local IP on port 25
It is Exchange 2003. The capture was after the firebox.
GW8 is the servers name.
Is the accountant getting the 5.1.1 on all emails sent to you, or just certain email addresses?
Do you have a full header from the NDR response he get's back?
Enable ALL logging on the Firebox in the Incoming SMTP Proxy and send a test message - then check the log file...
It seems that the problem right now is between the Firebox and Exchange. The thing is that "User unknown in virtual alias table" isn't a message from Exchange, so it may be the Firebox rejecting the mail... turn on all the logging on the Firebox, resend a test message, post the header and the log...
I dont have the full header of the bounce he is getting.
Something new developed over the weekend, now our sister office cannot email us and they are getting the same message. This is the bounce they got on their end:
Delivery has failed to these recipients or distribution lists:
Â
msmith@greenwayeng.com
The recipient's e-mail address was not found in the recipient's e-mail system. Microsoft Exchange will not try to redeliver this message for you. Please check the e-mail address and try resending this message, or provide the following diagnostic text to your system administrator.
Â
The following organization rejected your message: mailrtr12.ntelos.net.
Â
 _____ Â
Sent by Microsoft Exchange Server 2007
Â
Diagnostic information for administrators:
Â
Generating server: slsserver3.slssurveys.com
Â
msmith@greenwayeng.com
mailrtr12.ntelos.net #550 5.1.1 <msmith@greenwayeng.com>: Recipient address rejected: User unknown in virtual alias table ##
Â
Original message headers:
Â
Received: from slsserver3.slssurveys.com ([192.168.1.8]) by
 slsserver3.slssurveys.com ([192.168.1.8]) with mapi; Mon, 18 Apr 2011
 08:17:29 -0400
From: Deanna Beron <dberon@slssurveys.com>
To: "msmith@greenwayeng.com" <msmith@greenwayeng.com>
Date: Mon, 18 Apr 2011 08:17:27 -0400
Subject: FW: BROWNSTREET
Thread-Topic: BROWNSTREET
Thread-Index: Acv7tqWkkFswID6ITM+i02f9na
Message-ID: <423935B2EE5BE14E854152D74
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/mixed;
    boundary="_002_423935B2EE5
MIME-Version: 1.0

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
        DO_NOT_EDIT_THIS_FILE!_ver
5019368  04/18/11  09:07:21 n allow  out  eth1:0  48     tcp   20     128    10.10.10.10    67.211.153.135  27498   25     syn (SMTP)                        Â
5019398 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "TURN" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019408 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "PIPELINING" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019418 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "DSN" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019428 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "ENHANCEDSTATUSCODES" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019438 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "VRFY" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019448 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "X-EXPS" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019458 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "X-EXPS=LOGIN" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019468 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "X-LINK2STATE" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019478 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "XEXCH50" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
5019488 Â 04/18/11 Â 09:07:21 y smtp-proxy[24612] [10.10.10.10:27498 67.211.153.135:25] removing ESMTP keyword "OK" Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â
FYI - a lot of the words it is removing I have allowed under "Allow AUTH" in the ESMTP properties...
Still thinking that it is the Firebox.... can you turn off the SMTP Proxy to test? Then email should directly hit the Exchange server... if that works, then we know it's the Firebox... those keyword removals in the log do not seem right, as you said....






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
I cant turn off the SMTP proxy but I can remove it, save config as another name then save it to the firebox.
I'm sure that will require a reboot of the firebox so I will have to let all my VPN users know. I'm also pretty certain the mail will come in once I remove the proxy...
04/18/11 13:08 Â firewalld[139]: Â deny in eth0 48 tcp 20 107 178.34.39.1 64.181.96.242 54700 25 syn (default)

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
But yes, if the SMTP proxy was accepting the mail on behalf of Exchange, then there would be no port open through to the Exchange server, so you would need to add an exception for at least port 25 (if it lets you - maybe it forces it to go through the proxy?)...
An 'ANY' exception, if it works, should obviously only be left in place for the duration of the test....
220 mail.greenwayeng.com
ehlo kilmercpa.com250-Requested
250-SIZE
250 8bitmime
mail from: mkilmer@kilmercpa.com250 Requested mail action okay, completed
rcpt to: smiller@greenwayeng.com250
data354 Please start mail input.
subject: greenway.250 Mail queued for delivery.
quit221 Closing connection. Good bye.
Connection to host lost.
YET when I try to send email from the accountants network to mine I still get:
The following recipient(s) could not be reached:
   smiller@greenwayeng.com on 4/15/2011 4:08 PM
      The e-mail account does not exist at the organization this message was sent to.  Check the e-mail address, or contact the recipient directly to find out the correct address.
      <mail.kilmercpa.com #5.1.1 smtp;550 5.1.1 <smiller@greenwayeng.com>:






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Microsoft Mail Internet Headers Version 2.0
thread-index: AcwAKDbag/o4ShDpQJSQlC056q
X-SEM-SMTP: 1
Received: from kilmercpa.com ([67.211.153.135]) by mail.greenwayeng.com with Microsoft SMTPSVC(6.0.3790.1830); Thu, 21 Apr 2011 09:30:00 -0400
Content-Class: urn:content-classes:messag
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
Subject: test greenway
From: <mkilmer@kilmercpa.com>
Bcc:
Return-Path: <mkilmer@kilmercpa.com>
Message-ID: <GW8rLCCtgx8VUkRacUt000004
X-OriginalArrivalTime: 21 Apr 2011 13:30:00.0527 (UTC) FILETIME=[36D125F0:01CC002
Date: 21 Apr 2011 09:30:00 -0400
X-SEM-FILTER-STATUS: SfCf::adBlock::4e3e5411-9a
X-SEM-COMMUNITY-SCORE: 45
X-SEM-BLOCKED: 1
These lines:
X-SEM-FILTER-STATUS: SfCf::adBlock::4e3e5411-9a
X-SEM-COMMUNITY-SCORE: 45
X-SEM-BLOCKED: 1
show it being blocked. Why does it have a score of 45? The "user does not exist" may be a fake message to throw off spammers. Now you need to check your accountants domain and make sure they are not on any lists, if your spam filter is actively denying the email. And check the logs on SEM.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
were you able to look at the logs to see why SEM is blocking the message? At this point, it seems like your side is actively blocking those emails, and you need to figure out why that is.... or whitelist the email addresses...
The community filter is what is blocking it I believe. That means someone in our office somewhere along the line tagged it as spam. I've white listed both his email address and his domain and that did not help. Right now I am trying to find out how to reset the community filter.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Microsoft Mail Internet Headers Version 2.0
From: postmaster@kilmercpa.com
To: ckilmer@kilmercpa.com
Date: Mon, 25 Apr 2011 12:34:50 -0400
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-statu
      boundary="9B095B5ADSN=_01C
X-DSNContext: 7ce717b1 - 1194 - 00000002 - 00000000
Message-ID: <WtIIZS2TR00000034@mail.ki
Subject: Delivery Status Notification (Failure)
Â
--9B095B5ADSN=_01CBFE8A13E
Content-Type: text/plain; charset=unicode-1-1-utf-7
Â
--9B095B5ADSN=_01CBFE8A13E
Content-Type: message/delivery-status
Â
--9B095B5ADSN=_01CBFE8A13E
Content-Type: message/rfc822
Â
Return-Receipt-To: "Cathie Kilmer" <ckilmer@kilmercpa.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
      boundary="----_=_NextPart_
Disposition-Notification-T
Content-class: urn:content-classes:messag
X-MimeOLE: Produced By Microsoft Exchange V6.5
Subject: test
Date: Mon, 25 Apr 2011 12:34:49 -0400
Message-ID: <4E6508400506FF4EBE56EE597
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: test
thread-index: AcwDZrJe/TfbXw60TlOfazKzc8
From: "Cathie Kilmer" <ckilmer@kilmercpa.com>
To: <atvmxracer@gmail.com>,
      <smiller@greenwayeng.com>
Â
------_=_NextPart_001_01CC
Content-Type: text/plain;
      charset="us-ascii"
Content-Transfer-Encoding:
Â
------_=_NextPart_001_01CC
Content-Type: text/html;
      charset="us-ascii"
Content-Transfer-Encoding:
Â
Â
------_=_NextPart_001_01CC
Â
--9B095B5ADSN=_01CBFE8A13E
I was testing while on the phone with them and they get a bounce instantly, as soon as they hit send it is there.
      The e-mail account does not exist at the organization this message was sent to.  Check the e-mail address, or contact the recipient directly to find out the correct address.
      <mail.sosos.com #5.1.1 smtp;550 5.1.1 <apifer@greeneng.com>: Recipient address rejected: User unknown in virtual alias table>

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
      The e-mail account does not exist at the organization this message was sent to.  Check the e-mail address, or contact the recipient directly to find out the correct address.
      <mail.kilmercpa.com #5.1.1 smtp;550 5.1.1 <apifer@greenwayeng.com>: Recipient address rejected: User unknown in virtual alias table>
220 mail.greenwayeng.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at Thu, 28 Apr 2011 13:03:26 -0400
Not the "220 SMTP Service Ready" or "mail.greenwayeng.com" that the firewall gives (with the smtp proxy on).






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Exchange
--
Questions
--
Followers
Top Experts
Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.