Exchange
--
Questions
--
Followers
Top Experts
Im slightly confused. Â I have configured one of my hybrid servers with 0365. Â using the wizard and steps ive managed to create a remote mailbox. Â i have yet to move one from on prem to o365.
We also use Mimecast for our email filtering, security etc. Â I have added our on prem domain into o365 and verified this is valid, however i haven't updated any DNS setting though 123reg yet (i was concerned about affecting mail flow). Â
I have also setup inbound and outbound connectors in o365 for mail to flow to mimecast.
Can someone confirm that i must add (not edit or delete existing DNS records) MX, CNAM Eand SPF/TXT records now in order for mail to route from on prem to o365 and mimecast?
Were running split DNS internally on LAN.
Thanks for any pointers...
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
2. Are you sure i have read that the SPF must point to mimecast in order to use their mail servers? Â https://community.mimecast.com/docs/DOC-1623
3. okay will take a look at this. Â I know mimecast support has added umbrella domains or IPs here recently (no mention of KB or requirement until i spoke to them).
4. will look into this also.
My concern is making the changes to production domain which could affect mail....
I have tested mail flow and they are failing from the following routes/configs:
Pure test o365 domain hosted by MS - to external recipient and on premise mailboxes.
Remote mailbox in o365 (created by on prem server) - to on premise mailboxes.
2. I've added the MS and Mimecast SPF records to my external DNS config for all my domains in o365.
3. Can you elaborate on the IPs and where in mimecast?
4. Ive turned off TLS for my mimecast and hybrid connectors in o365. Â Still failing to route some of my emails. Â Errors:
From: Microsoft Outlook
Sent: 24 April 2016 11:00
To: o365 remotemailbox
Subject: Undeliverable: Test Appointment with attendee added (user1@domain.com) via o365 calendar in browser
Delivery has failed to these recipients or groups:
User One (user1@domain.com)
Your message wasn't delivered. Despite repeated attempts we were unable to deliver your message because validation of the recipient email system's certificate failed.
Contact the recipient by some other means (by phone, for example) and ask them to tell their email admin that it appears there's a problem with their SSL certificate or how it's configured on their email servers. Give them the error details shown below. It's likely that the recipient's email admin is the only one who can fix this problem.
For more information and tips to fix this issue see this article: http://go.microsoft.com/fwlink/?LinkId=389361.
Diagnostic information for administrators:
Generating server: AM3PR07MB0677.eurprd07.pro
Receiving server: AM3PR07MB0677.eurprd07.pro
user1@domain.com
4/24/2016 9:59:44 AM - Server at AM3PR07MB0677.eurprd07.pro
4/24/2016 9:51:46 AM - Server at mail.domain.com (WAN IP) returned '450 4.7.320 Certificate validation failed(SubjectMismatch)'
Original message headers:
Received: from AM3PR07MB0677.eurprd07.pro
 (2a01:111:e400:8839::25) by AM3PR07MB0677.eurprd07.pro
 (2a01:111:e400:8839::25) with Microsoft SMTP Server (TLS) id 15.1.466.12;
 Fri, 22 Apr 2016 09:52:33 +0000
Received: from AM3PR07MB0677.eurprd07.pro
 ([fe80::750f:1b9:c27d:b22a
 ([fe80::750f:1b9:c27d:b22a
 09:52:33 +0000
Content-Type: multipart/mixed;
    boundary="_000_AM3PR07MB06
From: o365 remotemailbox <o365remote@domain.com>
To: User One <user1@domain.com>
Subject: Test Appointment with attendee added (user1@domain.com) via
 o365 calendar in browser
Thread-Topic: Test Appointment with attendee added
 (user1@domain.com) via o365 calendar in browser
Thread-Index: AdGcfFenwshGZ2tJ0ESBRxhxks
Date: Fri, 22 Apr 2016 09:52:33 +0000
Message-ID: <AM3PR07MB06770EC3D7FA518D
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator: <AM3PR07MB06770EC3D7FA518D
authentication-results: domain.com; dkim=none (message not signed)
 header.d=none;domain.com; dmarc=none action=none
 header.from=domain.com;
x-ms-exchange-messagesentr
x-originating-ip: [WAN IP]
x-ms-office365-filtering-c
x-microsoft-exchange-diagn
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEI
x-ld-processed: 6d915662-fb5f-4138-a2c5-b0
x-exchange-antispam-report
x-exchange-antispam-report
X-Forefront-Antispam-Repor
spamdiagnosticoutput: 1:0
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-
 (UTC)
X-MS-Exchange-CrossTenant-
X-MS-Exchange-CrossTenant-
X-MS-Exchange-Transport-Cr
X-OrganizationHeadersPrese
X-OriginatorOrg: domain.com
X-CrossPremisesHeadersFilt
    AM3PR07MB0677.eurprd07.pro
i usually keep all of them
v=spf1 include:_netblocks.mimecas
Although Mimecast will say just to use them, but mail continuity might break if just in case mimecast have broken
More to read: https://community.mimecast.com/docs/DOC-1623
MX record will require to change so all inbound email will have spam filter (thats given), and depends on your tenant location, you will have a different MX record. you should get this from MImecast directly.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Left SPFs for both providers.
MS say the cert isnt valid as were on 2010: https://blogs.technet.microsoft.com/exchange/2016/02/19/important-notice-about-certificate-expiration-for-exchange-2013-hybrid-customers/
if could happening to you too (just saying)
on exchange online, if possible, you run get-outboundconnector | fl
on exchange on-premise, run get-sendconnector | fl
Â
that should show anything using certificate based routing
[PS] C:\Users\Desktop>Get-SendC
Creating a new session for implicit remoting of "Get-SendConnector" command...
AddressSpaces         : {SMTP:*;1}
AuthenticationCredential   :
Comment            :
ConnectedDomains       : {}
ConnectionInactivityTimeOu
DNSRoutingEnabled       : False
DomainSecureEnabled      : False
Enabled            : True
ErrorPolicies         : Default
ForceHELO Â Â Â Â Â Â Â Â Â Â : False
Fqdn             :
HomeMTA Â Â Â Â Â Â Â Â Â Â Â : Microsoft MTA
HomeMtaServerId        : exchange
Identity           : Mimecast Send Connector
IgnoreSTARTTLS Â Â Â Â Â Â Â : False
IsScopedConnector       : False
IsSmtpConnector        : True
LinkedReceiveConnector    :
MaxMessageSize        : 25 MB (26,214,400 bytes)
Name             : Mimecast Send Connector
Port             : 25
ProtocolLoggingLevel     : None
RequireOorg          : False
RequireTLS Â Â Â Â Â Â Â Â Â : False
SmartHostAuthMechanism    : None
SmartHosts          : {eu-smtp-outbound-1.mimeca
SmartHostsString       : eu-smtp-outbound-1.mimecas
SmtpMaxMessagesPerConnecti
SourceIPAddress        : 0.0.0.0
SourceRoutingGroup      : Exchange Routing Group (DWBGZMFD01QNBJR)
SourceTransportServers    : {exchange, exchange-DR}
TlsAuthLevel         :
TlsDomain           :
UseExternalDNSServersEnabl
AddressSpaces         : {smtp:tenantdomain.mail.on
AuthenticationCredential   :
Comment            :
ConnectedDomains       : {}
ConnectionInactivityTimeOu
DNSRoutingEnabled       : True
DomainSecureEnabled      : False
Enabled            : True
ErrorPolicies         : DowngradeAuthFailures
ForceHELO Â Â Â Â Â Â Â Â Â Â : False
Fqdn             : mail.domain.co.uk
HomeMTA Â Â Â Â Â Â Â Â Â Â Â : Microsoft MTA
HomeMtaServerId        : exchange-DR
Identity           : Outbound to Office 365
IgnoreSTARTTLS Â Â Â Â Â Â Â : False
IsScopedConnector       : False
IsSmtpConnector        : True
LinkedReceiveConnector    :
MaxMessageSize        : 10 MB (10,485,760 bytes)
Name             : Outbound to Office 365
Port             : 25
ProtocolLoggingLevel     : None
RequireOorg          : False
RequireTLS Â Â Â Â Â Â Â Â Â : True
SmartHostAuthMechanism    : None
SmartHosts          : {}
SmartHostsString       :
SmtpMaxMessagesPerConnecti
SourceIPAddress        : 0.0.0.0
SourceRoutingGroup      : Exchange Routing Group (DWBGZMFD01QNBJR)
SourceTransportServers    : {exchange-DR}
TlsAuthLevel         : DomainValidation
TlsDomain           : mail.protection.outlook.co
UseExternalDNSServersEnabl
On-Prem:
PS C:\Users\user> get-outboundconnector | fl
RunspaceId           : 3513a101-11da-4b1c-b3a4-26
Enabled            : False
UseMXRecord          : False
Comment            : Outbound connector to exchange2
ConnectorType         : OnPremises
ConnectorSource        : AdminUI
RecipientDomains        : {}
SmartHosts           : {mail.domain.co.uk}
TlsDomain           : mail.domain.co.uk
TlsSettings          : DomainValidation
IsTransportRuleScoped     : False
RouteAllMessagesViaOnPremi
CloudServicesMailEnabled    : True
AllAcceptedDomains       : True
TestMode            : False
LinkForModifiedConnector    : 00000000-0000-0000-0000-00
ValidationRecipients      : {user1@domain.co.uk}
IsValidated          : False
LastValidationTimestamp    : 27/04/2016 10:56:53
AdminDisplayName        :
ExchangeVersion        : 0.1 (8.0.535.0)
Name              : exchange2
DistinguishedName       : CN=exchange2,CN=Transport Settings,CN=Configuration,
                osoft.com,CN=Configuration
Identity            : exchange2
Guid              : 21bce97a-bb2f-458f-b434-9f
ObjectCategory         : EURPR07A004.PROD.OUTLOOK.C
ObjectClass          : {top, msExchSMTPOutboundConnecto
WhenChanged          : 27/04/2016 11:33:04
WhenCreated          : 26/04/2016 14:24:01
WhenChangedUTC Â Â Â Â Â Â Â Â : 27/04/2016 10:33:04
WhenCreatedUTC Â Â Â Â Â Â Â Â : 26/04/2016 13:24:01
OrganizationId         : EURPR07A004.PROD.OUTLOOK.C
Id               : exchange2
OriginatingServer       : VI1PR07A004DC01.EURPR07A00
IsValid            : True
ObjectState          : Unchanged
RunspaceId           : 3513a101-11da-4b1c-b3a4-26
Enabled            : True
UseMXRecord          : False
Comment            : Connector to send o365 emails to mimecast journaling.
ConnectorType         : Partner
ConnectorSource        : AdminUI
RecipientDomains        : {journal.testdomain.com, journal.domain.co.uk}
SmartHosts           : {eu-smtp-journal-1.mimecas
TlsDomain           :
TlsSettings          :
IsTransportRuleScoped     : False
RouteAllMessagesViaOnPremi
CloudServicesMailEnabled    : False
AllAcceptedDomains       : False
TestMode            : False
LinkForModifiedConnector    : 00000000-0000-0000-0000-00
ValidationRecipients      : {user1@domain.co.uk}
IsValidated          : False
LastValidationTimestamp    : 28/04/2016 14:56:07
AdminDisplayName        :
ExchangeVersion        : 0.1 (8.0.535.0)
Name              : Office 365 to Mimecast Journaling
DistinguishedName       : CN=Office 365 to Mimecast Journaling,CN=Transport Settings,CN=Configuration,
                ,DC=COM
Identity            : Office 365 to Mimecast Journaling
Guid              : 1d3a7661-68fd-4d0e-83ab-20
ObjectCategory         : EURPR07A004.PROD.OUTLOOK.C
ObjectClass          : {top, msExchSMTPOutboundConnecto
WhenChanged          : 28/04/2016 14:56:15
WhenCreated          : 21/04/2016 14:43:05
WhenChangedUTC Â Â Â Â Â Â Â Â : 28/04/2016 13:56:15
WhenCreatedUTC Â Â Â Â Â Â Â Â : 21/04/2016 13:43:05
OrganizationId         : EURPR07A004.PROD.OUTLOOK.C
Id               : Office 365 to Mimecast Journaling
OriginatingServer       : VI1PR07A004DC01.EURPR07A00
IsValid            : True
ObjectState          : Unchanged
RunspaceId           : 3513a101-11da-4b1c-b3a4-26
Enabled            : True
UseMXRecord          : False
Comment            : Outbound Delivery Routing for Office 365
ConnectorType         : Partner
ConnectorSource        : AdminUI
RecipientDomains        : {*}
SmartHosts           : {eu-smtp-o365-outbound-1.m
TlsDomain           :
TlsSettings          :
IsTransportRuleScoped     : False
RouteAllMessagesViaOnPremi
CloudServicesMailEnabled    : False
AllAcceptedDomains       : False
TestMode            : False
LinkForModifiedConnector    : 00000000-0000-0000-0000-00
ValidationRecipients      : {personalemail@hotmail.com
IsValidated          : True
LastValidationTimestamp    : 27/04/2016 16:39:38
AdminDisplayName        :
ExchangeVersion        : 0.1 (8.0.535.0)
Name              : Outbound Delivery Routing for Office 365
DistinguishedName       : CN=Outbound Delivery Routing for Office 365,CN=Transport Settings,CN=Configuration,
                OUTLOOK,DC=COM
Identity            : Outbound Delivery Routing for Office 365
Guid              : 290dfc25-2c05-476e-8eec-ff
ObjectCategory         : EURPR07A004.PROD.OUTLOOK.C
ObjectClass          : {top, msExchSMTPOutboundConnecto
WhenChanged          : 27/04/2016 16:39:48
WhenCreated          : 22/04/2016 15:15:04
WhenChangedUTC Â Â Â Â Â Â Â Â : 27/04/2016 15:39:48
WhenCreatedUTC Â Â Â Â Â Â Â Â : 22/04/2016 14:15:04
OrganizationId         : EURPR07A004.PROD.OUTLOOK.C
Id               : Outbound Delivery Routing for Office 365
OriginatingServer       : VI1PR07A004DC01.EURPR07A00
IsValid            : True
ObjectState          : Unchanged
RunspaceId           : 3513a101-11da-4b1c-b3a4-26
Enabled            : True
UseMXRecord          : False
Comment            : ZY1RDoJADAXnQiCsrEiy8S4rro
                IjFyI9iOVfNVfpM6anSoGa6SXG
ConnectorType         : OnPremises
ConnectorSource        : AdminUI
RecipientDomains        : {domain.co.uk}
SmartHosts           : {mail.domain.co.uk}
TlsDomain           :
TlsSettings          :
IsTransportRuleScoped     : False
RouteAllMessagesViaOnPremi
CloudServicesMailEnabled    : True
AllAcceptedDomains       : False
TestMode            : False
LinkForModifiedConnector    : 00000000-0000-0000-0000-00
ValidationRecipients      : {user1@domain.co.uk}
IsValidated          : True
LastValidationTimestamp    : 27/04/2016 11:26:21
AdminDisplayName        :
ExchangeVersion        : 0.1 (8.0.535.0)
Name              : Outbound to f821c266-7256-4b87-a9d1-e2
DistinguishedName       : CN=Outbound to f821c266-7256-4b87-a9d1-e2
                ion,CN=tenantdomain.onmicr
                PROD,DC=OUTLOOK,DC=COM
Identity            : Outbound to f821c266-7256-4b87-a9d1-e2
Guid              : cde5e305-0664-46c9-8a4e-cf
ObjectCategory         : EURPR07A004.PROD.OUTLOOK.C
ObjectClass          : {top, msExchSMTPOutboundConnecto
WhenChanged          : 27/04/2016 11:26:44
WhenCreated          : 21/04/2016 15:50:11
WhenChangedUTC Â Â Â Â Â Â Â Â : 27/04/2016 10:26:44
WhenCreatedUTC Â Â Â Â Â Â Â Â : 21/04/2016 14:50:11
OrganizationId         : EURPR07A004.PROD.OUTLOOK.C
Id               : Outbound to f821c266-7256-4b87-a9d1-e2
OriginatingServer       : VI1PR07A004DC01.EURPR07A00
IsValid            : True
ObjectState          : Unchanged
results edited slightly of course..

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
get-sendconnector "Outbound to Office 365" | set-sendconnector -smarthost <tenantname>.mail.protecti
get-sendconnector "Outbound to Office 365" | Set-SendConnector -TlsCertificateName <Â the name of your certificate>
Please do not run the command above first.
Try to run the Hybrid configuration wizard. because it should be all created properly when you run the hybrid configuration wizard.
open Exchange management console - and make sure you logon to Office 365
then go to Organisation configuration (onpremise), click manage hybrid configuration
more read: http://www.msexchange.org/articles-tutorials/office-365/exchange-online/using-hybrid-configuration-wizard-exchange-2010-service-pack-2-part3.html






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Could you please answer those questions for me ?
1- What Exchange server version do you have now?
From the send connector I can see that you have 2007 In order to have Hybrid working without an issue you'll need to have at least one Exchange 2010 SP3 (At least) for the Hybrid to work.
2- Have you entered Microsoft Exchange online/Online Protection/Hybrid IPs to your SMTP gateway's whitelist?
If you don't do this you won't be able to get e-mails.
3- Have you validated Outbound emails on office 365 Exchange online's Mail flow-Connectors tab ?
I have Mimecast IPS added yes.
Yes

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Microsoft has also made a mistake in one article which I had problem with when I deployed a similar scenario with an on-prem Gateway.
The Article is here
https://technet.microsoft.com/en-us/library/dn163581%28v=exchg.150%29.aspx?f=255&MSPPError=-2147217396
In this article MS says they have removed some IPS in February 24, 2016 but I have noticed in the gateway that these IPs are still being used.
Removed 23.103.148.0/22 207.46.163.128/26 207.46.163.192/27 207.46.163.224/27 23.103.145.128/27 23.103.145.192/27 213.199.154.0/26 213.199.154.64/26 213.199.154.128/27 207.46.51.64/27 207.46.51.96/27 134.170.132.0/24
make sure you add them all.
this log told me it is a Certificate issue, rerun the hybrid configuration wizard should fix the issues.
4/24/2016 9:51:46 AM - Server at mail.domain.com (WAN IP) returned '450 4.7.320 Certificate validation failed(SubjectMismatch)'
DNS for our production domain is now correct as much i think its going to be.
Mimecast IPs added as allowed in 365.
Whats confusing now is that im not sure which platform inbound and outbound emails are going from/to...






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
please remove the CNAME record of autodiscover, since you are still in hybrid, it need to go onpremise, not office 365.
and MX record of 11,
then rerun HCW.
In the event of the Mimecast service or MX records failing to deliver mail, i have added the MX record for Microsoft to handle email. Â Are you sure this should be removed?
HCW still give me the error...

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
The error is stating a certificate SAN Mismatch.. The TLS in most cases doesn't work with a gateway between Exchange online and On-prem in a hybrid scenarios.
4/24/2016 9:59:44 AM - Server at AM3PR07MB0677.eurprd07.pro
4/24/2016 9:51:46 AM - Server at mail.domain.com (WAN IP) returned '450 4.7.320 Certificate validation failed(SubjectMismatch)'
Im really stumped now as most of the tests are failing within the remote analyser.... Â
EAS is working fine on prem so certs must be ok..






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Exchange
--
Questions
--
Followers
Top Experts
Exchange is the server side of a collaborative application product that is part of the Microsoft Server infrastructure. Exchange's major features include email, calendaring, contacts and tasks, support for mobile and web-based access to information, and support for data storage.