Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Exchange smart host send connector connexion timed out 421 4.4.1

Posted on 2014-04-30
Medium Priority
Last Modified: 2014-07-07
Hi Experts,

We encounter a strange issue on a SBS 2011 with Exchange 2010 SP3 server. We send emails through our ISP smar host. Everything worked great since a long time and a day this error appeared:

541 4.4.0 Primary target IP address responded with: "421 4.4.1 Connection timed out." Attempted failover to alternate host, but that did not succeed. Either there are no alternate hosts, or delivery failed to all alternate hosts.

We contacted the ISP and after some tests, they claim that the problem couldn't be from their side.

I then tried to create a brand new send connector with this smart host with DNS name and then with IP address with the same result. I created a NAT rule on our USG 100 to give the right IP from our pool to the server which had the gateway one and tested it successfully. The mails are coming from the right IP and the reverse DNS is OK too.

I tried successfully  to send mail with telnet from our Exchange server through the ISP smart host server. The mail came with the good source IP and host name too.

What can I do now please?

Thank you in advance for your precious help, best regards,
Question by:jet-info
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
  • +2
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40032334
ISP tech support lie and their primary task is to find something to blame the problem on that isn't their network, or to utter the magic words "we don't support that".

As long as you work on that basis, then your sanity will be fine.

Can you telnet in to port 25 of their server from your server? From another machine? If not, then something is wrong with their setup.
Can you telnet in to port 25 of another mail server? If so, then that definitely points to a problem with their server.

LVL 31

Expert Comment

by:Gareth Gudger
ID: 40033516
I agree with Simon. The number of times I have called an ISP, they claim nothing is wrong, you persist, they go on hold "to check" and then it magically starts working is uncanny.

But back on topic. Normally when you get this error the problem is with the smart host. As Simon said, try to Telnet to it.

I am curious about the bigger picture here. You mentioned you have configured your mail server to always send out on the same IP and you have a reverse DNS configured for this IP. Any particular reason you are using the smart host and not just sending direct to DNS in the Send Connector?

Expert Comment

ID: 40035144
I had this exact issue earlier this week and the issue was down to a problem the ISP were having.

Did you confirm with the ISP support team that the smarthost name / IP address are correct?

Speak with the ISP support team and ask them to escalate the call, if nothing has changed your end then it can only be something their end...
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.


Author Comment

ID: 40043835
Thank you for your answers,
I was sick, so excuse me for the delay...

When I test our customers Mail Server with MXToolBox, I receive no more error. The new NAT rule seems to have corrected the previous open relay error, which was a possible open relay configuration error because of quick connection lost, MXTB had not the necessary time to try to relay...

I can send mails with telnet from the customer's site and ours. We are both customers of the same ISP, which authorize only his customers (IP Range) to use this smart host.

I can send telnet mails from the customers server through another of ours customers mail server. So what can I do in more please?

Thank you in advance for your help !
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40049777
If you are both on the same ISP then that points to the smart host being the cause and you have to bring the ISP in on the issue. If you are send email to other sites without a problem it is somewhere within the ISP network.


Author Comment

ID: 40067559
I tested to switch back to the ISP smart host this morning  and it worked for about 3 hours. Then it stopped working with the exactly same "Connection timed out" error. I wrote to the ISP and wait for their answer.
I looked up in the send log (C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\ProtocolLog\SmtpSend) and found all successfully connexions but no error message. It just stopped writing in the log when the error occured. In which log file can I find it please?

Thanks in advance for your help, best regards,

Author Comment

ID: 40105289
New try, same result. I activated the smart host send connector ans disabled the other one for one hour in accordance with the ISP. We sent approximately 20 mails. The timed out connection error occurred three times. If we suspend and resume in the queue viewer, mails were sent for a while and the error occurred again...
The ISP can see only successful connections. In our Exchange smtpsend log, we can see only successful connections too. In which log could we see the timed out connection please ?
Nothing in the Windows eventvwr logs too...

Thank you in advance for your help !
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 1000 total points
ID: 40105885
I would start pointing the finger at the firewall.
Although I would also be considering stripping anything that could be scanning SMTP traffic off the server - so AV software, anti-spam etc.


Author Comment

ID: 40117435
Here is the ISP response :

The technicians who are responsible for our outgoing mail have verified your logfile with our SMTP servers.

From 12:04:46 CEST we only see the "CONNECT", but no transmission dates (or data??). The sending "EHLO" (from "2014-06-02T10: 04:46.729 Z, smart host, 08D13C876463D1DB, 20,,,> EHLO, ") does not happen here.

We can not find any problems on our side. Since there are no such problems with our other customers.
LVL 31

Accepted Solution

Gareth Gudger earned 1000 total points
ID: 40118868
What about dropping the smart host? As long as you have all the right PTR and SPF records in there, you shouldn't need to use your ISP as a smart host.
LVL 40

Expert Comment

ID: 40119101
Well does your ISP limit the number of addressees on a mail? it may be that they say 5 is a limit. if you have 6 in total To: + CC: + BCC: it can be rejected with 421...

Author Closing Comment

ID: 40180988
Sorry for the delay, we are sticking on the backup send connector for the moment. We'll test it again when we have more time. We'll post a new answer later.

Thank you for your help !

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question