Solved

email sent from domain a to a list in domain b unable to relay

Posted on 2014-03-14
6
427 Views
Last Modified: 2014-03-20
We are using exchange 2010 and recently implemented the policy where people can't relay through our exchange server without either authenticating or we allow their IP.  When we did this, when employees send to a distribution list on another organization's mail server but includes email addresses with our domain in them, the message doesn't get delivered and the 550 5.7.1 message comes up.  I'll try to show an example:

We are domain A and we have employees that sit in different organizations.  Two specific ones are showing problems right now, we'll call them domain B and domain C.

When Joe from domain A sends an email to the distribution list with the email address list@domainb.com (which includes email addresses from domain A) those people in Domain A do not get it.  Same happens to those who send to domainc.com.  This JUST started happening this week and it ONLY seems to be happening when users send to distribution lists.  If a user within the different organizations (domain B and domain C) send, it goes out just fine.  

How can I tweak it so our employees who use our email can send to these lists and have our other employees get them?  Thank you.
0
Comment
Question by:ecsitadmin
  • 3
  • 2
6 Comments
 
LVL 25

Expert Comment

by:Mohammed Khawaja
ID: 39930263
By default distribution lists requires authenticated users to be able to relay.  You could disable authenticated user option for the distribution lists.
0
 

Author Comment

by:ecsitadmin
ID: 39930334
it's not our distribution lists.  The Distribution lists are housed on different organizations' mail servers.  It's not that option because it's at least two different organizations and i'd say it's a pretty big coincidence that those two all of a sudden require DL's to be authenticated now.
0
 
LVL 25

Expert Comment

by:Mohammed Khawaja
ID: 39930348
If the DLs are in different organization servers and if they try to relay through your server then it will be rejected.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:ecsitadmin
ID: 39930355
they're not trying to relay.  At least  they shouldn't be.  They're just trying to send mail to the recipients.  So if you are on a distribution list on another organization, and I try to send to that email address, it just wants to deliver it to you.  They're not trying to relay.
0
 

Author Comment

by:ecsitadmin
ID: 39930417
This is the best way I can put it without giving away specifics.

I reside with org. a an email user1@domaina.com

I am trying to email a distribution list at a different organization (domainb.com), which has email addresses from domaina.com on it and domainb.com on it.  If I email from my email address user1@domain.com to list@domainb.com, it gets to those within the organization but once it tries to send back to domaina.com, it gets rejected.  Same with domainc.com.  the relaying has already occurred on domaina.com's exchange server.  All domainb.com's mail server should be doing is just sending the mail back through domainb.com.  But for some reason when sending to the DL on domainb.com (and domainc.com)'s mail servers, our exchange server acts like it's trying to relay.  It shouldn't be.  That is my problem.
0
 
LVL 26

Accepted Solution

by:
skullnobrains earned 500 total points
ID: 39931488
i'd assume the problem is not really about relaying incoming message. most likely exchange rejects the SENDER as being a member of your domain trying to send email from a foreign address. it probably considered the address was spoofed and rejects the mail regarding of the recipient

i don't know about your policies, but i'd assume you somehow apply this policy on senders from your domain
- allow mail from authenticated users
- allow mail from LAN addresses
- reject everything else

this is unrelated with the rules that allows delivery to your domain addresses from foreign domains

you can check your logs if you're unsure

in order to solve this issue, i don't see anything very smart :

- allowing their ips to send impersonating members of your domain is probably not really a good idea (but may be acceptable)
- allowing anything that is intended to members of your domain to go through regardless the sender is definitely NOT a good idea spam-wise
- allowing the combination of their ips, a sender from your domain and a recipient on your domain looks safe enough
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
PCI compliance 16 33
open ost file into new machine? 7 55
CSS: Making Pure CSS read more boxes thinner 5 31
How does email route to destination? 8 15
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Data breaches are on the rise, and companies are preparing by boosting their cybersecurity budgets. According to the Cybersecurity Market Report (http://www.cybersecurityventures.com/cybersecurity-market-report), worldwide spending on cybersecurity …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question