troubleshooting Question

Understanding exchange SMTP Logs to help troubleshoot local app issue

Avatar of nhnerd
nhnerdFlag for United States of America asked on
ExchangeEmail ServersEmail ProtocolsSBS
5 Comments2 Solutions411 ViewsLast Modified:
I'm working with a third party programming sending emails through a special connector on my exchange. there are supposed to be 150+ emails sent through the connector. there are only about 21 going through. the first 20 go out then about 2.5 hrs one last email goes. the programmers says it is not them, but my SMTP logs only show 24 emails going through the connector with 3 rejected do to bad "MAIL FROM :" The program is authenticating as one user and sending as another. that's easy to fix.

But in the logs, i see the following initial connection stream. Seams a little off. can someone explain this; There looks to me 2 login / authentication connections (domain name and user name change to protect the Innocent)

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500
EHLO Local Program server
EHLO Local Program server
250-(Local Email Server) Hello [192.168.38.29]
250-SIZE 31457280
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-X-ANONYMOUSTLS
250-AUTH NTLM LOGIN
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-XEXCH50
250-XRDST
250 XSHADOW

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
250-(Local Email Server) Hello [192.168.38.29]
250-SIZE 31457280
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-X-ANONYMOUSTLS
250-AUTH NTLM LOGIN
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-XEXCH50
250-XRDST
250 XSHADOW
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500
EHLO Local Program server
AUTH ntlm
AUTH ntlm
250-(Local Email Server) Hello [192.168.38.29]
250-SIZE 31457280
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-X-ANONYMOUSTLS
250-AUTH NTLM LOGIN
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-XEXCH50
250-XRDST
250 XSHADOW
334 <authentication response>
334 <authentication response>
AUTH ntlm
SMTPSubmit SMTPAcceptAnyRecipient BypassAntiSpam AcceptRoutingHeaders
domain\user
SMTPSubmit SMTPAcceptAnyRecipient BypassAntiSpam AcceptRoutingHeaders
domain\user

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
334 <authentication response>
235 2.7.0 Authentication successful
235 2.7.0 Authentication successful
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
SMTPSubmit SMTPAcceptAnyRecipient BypassAntiSpam AcceptRoutingHeaders
domain\user
MAIL FROM:<sender@publicdomain.com>
08D3019FC1DFE572;2015-12-23T16:24:54.266Z;1
MAIL FROM:<sender@publicdomain.com>
08D3019FC1DFE573;2015-12-23T16:24:54.266Z;1
EHLO Local Program server
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
235 2.7.0 Authentication successful
250 2.1.0 Sender OK
250 2.1.0 Sender OK
250-(Local Email Server) Hello [192.168.38.29]
250-SIZE 31457280
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-X-ANONYMOUSTLS
250-AUTH NTLM LOGIN
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-XEXCH50
250-XRDST
250 XSHADOW
EHLO Local Program server
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500

SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders
MAIL FROM:<sender@publicdomain.com>
08D3019FC1DFE574;2015-12-23T16:24:54.282Z;1
RCPT TO:<recpt-1@publicemailaddress.com>
RCPT TO:<recpt-2@publicemailaddress.com>
AUTH ntlm
250-(Local Email Server) Hello [192.168.38.29]
250-SIZE 31457280
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-X-ANONYMOUSTLS
250-AUTH NTLM LOGIN
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-XEXCH50
250-XRDST
250 XSHADOW
EHLOLocal Program server
220 (Local Email Server) Microsoft ESMTP MAIL Service ready at Wed, 23 Dec 2015 11:24:53 -0500
250 2.1.0 Sender OK
250 2.1.5 Recipient OK
250 2.1.5 Recipient OK
334 <authentication response>

From here the individual email are sent.

it seams the local program is creating 2 connection and then sending through me. but I'm a lonely network admin not an exchange export
ASKER CERTIFIED SOLUTION
Join our community to see this answer!
Unlock 2 Answers and 5 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 5 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros