Email sent from Outlook, OWA or iPhone - Exchange 2010

Hi all,

is there any way to tell if a particular email was sent from Outlook, OWA or an iPhone.

We have a user from whose account an email was being sent but the user is denying that he sent that email. Now I need to figure out which device it went from so that we can focus on that area. iPhones are controlled through Airwatch.

Thanks.
LVL 3
Exchange UserSystems AdministratorAsked:
Who is Participating?
 
Adam BrownConnect With a Mentor Sr Solutions ArchitectCommented:
The client data is contained in the message tracking log under the SourceContext variable. http://www.msexchange.org/kbase/ExchangeServerTips/ExchangeServer2013/ManagementAdministration/determine-clients-used-send-emails.html has some information on how to examine information in the tracking log. The following command is edited to show you the source data for all emails since august first:
Get-TransportService | Get-MessageTrackingLog -ResultSize Unlimited -Start 08/11/2016 -EventID SUBMIT | select sender,recipient,subject,sourcecontext

Open in new window

0
 
Gaurav SinghConnect With a Mentor Solution ArchitectCommented:
you can check the Email headers, that gives some information, check lime MIME type in email header
0
 
pony10usCommented:
Also look at the sender's IP in the header.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
Exchange UserSystems AdministratorAuthor Commented:
I analyzed the 2 headers, one sent from my iPhone and the other from Outlook. The MIME version says 1.0 for both.

But when email is being sent from Outlook, the message ID has 'some ID'@serverFQDN.domain.local

When sending from iPhone, message ID is showing 'some ID'@domain.local

Any ideas ?
0
 
Exchange UserSystems AdministratorAuthor Commented:
Get-TransportService is not recognized by Exchange 2010's EMS ?
0
 
Exchange UserSystems AdministratorAuthor Commented:
@Adam I tried doing that with the toolbox option Tracking Log Explorer in the EMC. I have the data in front of me. Source Context here has different types of information. How do we read it ? Any ideas.
0
 
pony10usConnect With a Mentor Commented:
The client type in the log created using Adam's solution should show you what you want to know.

MOMT = Outlook
OWA = Outlook Web Access
AirSync = Active Sync (usually a phone/pad/etc)

For more information you can look at:  http://markgossa.blogspot.com/2015/11/exchange-what-type-of-client-sent-email.html
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.