Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

X500 addresses in Exchange 2010

Posted on 2013-05-22
Last Modified: 2014-07-22
Hi guys,

We did a migration from server 2003 to SBS 2011 a few months back. We had some issues with X500 addresses, which I learnt all about once we ran in to the problems.

So I went through and added everyone's X500 addresses to their email addresses. Everything seems to be working fine until now. I get a user saying that the X500 address can't be resolved AGAIN and it always seems to be for this specific user. I know you're supposed to be able to just derive the X500 address from the diagnostic error but I've done that (also with variants) and seems to keep happening.

Can anyone tell me what the X500 address should be for this particular user based on this diagnostics?


Delivery has failed to these recipients or groups:
Firstname Lastname
The e-mail address you entered couldn't be found. Please check the recipient's e-mail address and try to resend the message. If the problem continues, please contact your helpdesk.
Diagnostic information for administrators:
Generating server: BON-VSBS-01.domain.local
#550 5.1.1 RESOLVER.ADR.ExRecipNotFound; not found ##
Original message headers:
Received: from BON-VSBS-01.domain.local ([fe80::3cef:11cb:bf8c:967]) by
 BON-VSBS-01.domain.local ([fe80::3cef:11cb:bf8c:967%10]) with mapi id
 14.01.0438.000; Wed, 22 May 2013 16:23:05 +1000
Content-Type: application/ms-tnef; name="winmail.dat"
Content-Transfer-Encoding: binary
From: Firstname Lastname <sender@domain.com.au>
To: Firstname Lastname <receiver@domain.com.au>
Subject: Canceled: Subject
Thread-Topic: Subject
Thread-Index: Ac5WtKKttQskIHo7TyakT3+nq1NP5QAAC2Rw
Importance: high
X-Priority: 1
Date: Wed, 22 May 2013 16:23:04 +1000
Message-ID: <5F2B01C0166AD14A91F15FA8EE4455C837618BA3@BON-VSBS-01.domain.local>
Accept-Language: en-AU, en-US
Content-Language: en-US
X-MS-TNEF-Correlator: <5F2B01C0166AD14A91F15FA8EE4455C837618BA3@BON-VSBS-01.domain.local>
MIME-Version: 1.0
X-Originating-IP: []
Question by:Talds_Alouds
LVL 12

Expert Comment

ID: 39187323

We need to add a new X500 address to the user mailbox from Exchange Management Console. To do that, we need to first create it in the right format.
First step is to get rid of the _ and convert them to /

Now the tricky part:
Look closely and you see some numbers like +20, +28 etc… Wondering what they are?
 +20 is a SPACE
 +28 and +29 are ( and ) respectively
 +2E is .

LVL 17

Expert Comment

ID: 39187400
@SreRaj... don't just cut and paste without adding to the link...

You need to click on the name in the NDR and post the resolver address, this will give you the info you need to create the correct X500 address

Author Comment

ID: 39189309
I should tell you that "Firstname Lastname" below is a hyperlink to this address:

Delivery has failed to these recipients or groups:
Firstname Lastname (Hyperlink:mailto:IMCEAEX-_O%3DDOMAINORGANISATION_OU%3DFIRST%2B20ADMINISTRATIVE%2B20GROUP_CN%3DRECIPIENTS_CN%3DFirstname@domain.local

So given the whole NDR and this link above, these are the addresses that the user already has and has had for the last couple of months. Can someone please confirm that these are right?



/O=DomainOgranisation/OU=First Administrative Group/CN=Recipients/CN=Firstname

Every user has these 3 addresses (with their names changed respectively. Everything you see above is exactly what's in the address (with names changed obviously), but capital letters are all the same though.

Over the months, I've noticed that people have had more problems sending to this user in particular although this could just be because other users don't report the problem.

See anything wrong?

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

LVL 12

Expert Comment

ID: 39190011
Last part of the X500 address contains user alias. So the alias should be as follows.


The X500 addresses looks fine.

Exchange uses the legacyExchangeDN attribute for sending mails within the organization. legacyExchangeDN gets changed when a user changes name or when mailbox is re-created or after a migration. The new legacyExchangeDN may not be recognized by the Exchange system and this triggerst the NDR.

Author Comment

ID: 39190045
Yeah so I'm confused. We got the same legacy exchangeDN. So how can it keep failing?

I don't know much about this stuff, although it doesn't SEEM overly complicated. Is not having the x500 record the ONLY way this NDR would be triggered?

LVL 12

Expert Comment

ID: 39190170
NDR is triggered when user reply to an old mail. The old mail will be having information regarding the old legacyExchangeDN as Outlook is still caching old legacyExchangeDN information. Exchange will try to forward mail to that and since it got changed, NDR will be triggered.

Now, while replying to the old mail, if the user removes the cached address and does a fresh search from the GAL for this user then it will not trigger this NDR.

By adding the old legacyExchangeDN as X500 address, when Exchange system looks for old legacyExchangeDN, it will be found as additional mail address and mail will get delivered without a NDR.

Author Comment

ID: 39190217
Thanks...I get all that but why is it still happening when I've got these X500 addresses in there?
LVL 12

Expert Comment

ID: 39190294
Could you please provide one more NDR? There is differences in the addresses you have provided earlier. We will try to confirm which is the correct one. Also please try testing by replying to the user by searching for the user from GAL. Following are the earlier ones.



Also, please let us know what is the value of the attribute legacyExchangeDN now. You will be able to find it thru ADSIEdit.msc.

Author Comment

ID: 39227895

I haven't been notified of this happening again. It must have been a once off?
LVL 12

Accepted Solution

SreRaj earned 500 total points
ID: 39276996
Normally this happens when users reply to an old mail. If they compose a new mail and select this user's address from GAL, this error will not be generated. This is because GAL will be having updated information of the user. When replying to old mail, outlook will use the old mail address which is cached in outlook and this results in error.

Expert Comment

ID: 40213520
Talds_Alouds - I dealt with this issue for a client recently and the easiest way to get the correct X500 address causing the rejection NDR, is to click on the Name Link in the NDR email. It should open a new email to the fully qualified rejected X500 address, allowing you to simply copy and paste it into the Exchange Mailbox properties.

I found it easy to access the NDR email via the user's mailbox using OWA on a browser on the Exchange server.

In our client's case there was no previous migration, it was just simply a case where a corrupt mailbox was exported to PST, deleted, and then recreated. The Exchange X500 address of the recreated mailbox had different alphanumeric characters suffixed to the end of the alias name, when compared to the original.

As others have posted, running this command in Exchange Management Shell will tell you the current X500 address of the recreated mailbox:  Get-Mailbox username | fl LegacyExchangeDN  

Checking the rejected Name Link in the NDR email will show you the old X500 address of the original mailbox. They will be different, hence the NDR.

Adding a custom X500 address into the recreated mailbox's properties, using the address from the NDR link, should resolve the NDR issue.

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Utilizing an array to gracefully append to a list of EmailAddresses
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question