Inbound Mail TLS Issue for certain domains

Dear Experts,
I have a client, we have recently moved to exchange 2013 with mail being proxied via a Sophos UTM. The system works well and the client recieves inexcess of 8000+ spam emails daily which the UTM catches.

One of the suppliers that emails in gets this message:

Delay Report
Your message:
Re: Test Outbound
addressed to: user@domain.com
has the following delivery status:
451 4.7.5 [internal] TLS negotiation failed
What should you do?
This message is an informational Delivery Status Notification and does not require any further action.
Delivery to the recipients indicated above has been delayed.  You do not need to resend this message.  The server will continue to attempt message delivery.


I do not see the attempted delivery on the UTM SMTP logs, where as all the other mail is there whether it is being delivered to the exchange server or being quarantined or blackholed. I have also excluded the domain.com from TLS checking on the UTM, still nothing.

It is my belief the issue is with the sending servers? Could someone please help.
bluewaveitAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Rajitha ChimmaniCommented:
Appears to be on the sending end. It appears they have a forced TLS configuration. Have them disable TLS and try sending an email
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
bluewaveitAuthor Commented:
Thank you for your comment, I have completed yet testing and have passed it back to their IT support team.
0
pizzaman7ConsultantCommented:
This is terrible advice.  I have Exchange 2013 SP1 with a Sophos UTM proxying the mails as well.  I had to upgrade to version 9.304-9 for the TLS Negotiation to take place between Exchange and GMail.  Good luck trying to get GMail to stop sending out mail requiring TLS.  It probably is a good thing.  I did not have to do anything else.  By default Sophos will adapt automatically to the type of negotiation the sending server requires.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.