Exchange 2010 External Out of Office not working - "550 5.5.0. Sender Domain is empty"

Hello Experts,

Our client's external OoO is not working or more likely being rejected. When I did Exchange message tracking on the automated reply, it fails with an error message: "550 5.5.0. Sender Domain is empty". The customer is using a Smart host pointing to our Fortimail appliance for a spam filtering, but I can't find the message being logged on our end anywhere (Fortimail). I've also disabled any Content filtering on customer's Exchange(for testing only) to no avail.

I know a workaround would be to use DNS (MX) records to route the mail out instead, but they'd get smashed with SPAM obviously..
Was somebody else experiencing this please?

Thanks a lot
Vlas
LVL 4
Vlastimil SopuchDirectorAsked:
Who is Participating?
 
Vlastimil SopuchConnect With a Mentor DirectorAuthor Commented:
The fix was in Fortimail appliance / Policy / Policies - creating a new policy for the customer and unchecking the "Reject empty domains" under "Unauthenticated Session Settings".
0
 
Andy MInternal Systems ManagerCommented:
I'm assuming it all works fine internally.

As you are not seeing the Out Of Office on the logs on your fortinet then the problem would lie either with the client's Exchange or the smart host system. I've known some smarthosts utilsie anti-spam features that prevent out of office responses being sent previously.

On the client's exchange do the smtp logs show the out of office being sent to the smart host successfully or not?

You could temporarily setup a new send connector that just goes directly out (no smart host, just use DNS/MX). Sent that as the primary send connector, run some tests and then set it back again. If Out of Office works fine on that then I'd be looking at the smart host as being the issue in which case you'd need to contact them about it.
0
 
Vlastimil SopuchDirectorAuthor Commented:
Yes, you're correct. The internal OoO works fine.

Hmmm, just did a test with the smart host off, using the DNS MX records and it fails with exactly the same error: "550 5.5.0. Sender Domain is empty" ..when I do Exchange message tracking for automatic reply.
- I haven't restarted the Exchange Transport service" before the test. Might need to re-test after hours again.
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
Andy MConnect With a Mentor Internal Systems ManagerCommented:
Came across this article which may be of use - same issue with Exchange 2007 and Fortinet systems (plus does mention same thing on Exchange 2010).

https://forum.fortinet.com/tm.aspx?m=81879

Yeah, if you make any changes to send/receive connectors it is always worth restarting the Exchange transport service as well to ensure the changes are correctly applied.
0
 
Vlastimil SopuchDirectorAuthor Commented:
I came across similar article, but can you tell which policy to edit? FortiMail_PolicyThanks a lot!
0
 
Andy MInternal Systems ManagerCommented:
I would guess it would be 16 and 17. Unfortunately I don't have a great deal of experience specifically with fortinet applications so not much use in actually changing the settings but those two seems to be rules applying to external systems.
0
 
Vlastimil SopuchDirectorAuthor Commented:
I'm attaching all 4 policies currently created for review. If someone with more networking background could suggest what needs to be changed please. Or should a new policy be created? Thanks Fortimail_Policy.png
0
 
Vlastimil SopuchDirectorAuthor Commented:
Thank you Andy M for your help with this! Appreciated.
0
 
Vlastimil SopuchDirectorAuthor Commented:
The issue was resolved by further testing myself at the end.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.