Solved

Exchange 2010 External Out of Office not working - "550 5.5.0. Sender Domain is empty"

Posted on 2016-09-12
9
28 Views
Last Modified: 2016-10-14
Hello Experts,

Our client's external OoO is not working or more likely being rejected. When I did Exchange message tracking on the automated reply, it fails with an error message: "550 5.5.0. Sender Domain is empty". The customer is using a Smart host pointing to our Fortimail appliance for a spam filtering, but I can't find the message being logged on our end anywhere (Fortimail). I've also disabled any Content filtering on customer's Exchange(for testing only) to no avail.

I know a workaround would be to use DNS (MX) records to route the mail out instead, but they'd get smashed with SPAM obviously..
Was somebody else experiencing this please?

Thanks a lot
Vlas
0
Comment
Question by:Vlastimil Sopuch
  • 6
  • 3
9 Comments
 
LVL 13

Expert Comment

by:Andy M
Comment Utility
I'm assuming it all works fine internally.

As you are not seeing the Out Of Office on the logs on your fortinet then the problem would lie either with the client's Exchange or the smart host system. I've known some smarthosts utilsie anti-spam features that prevent out of office responses being sent previously.

On the client's exchange do the smtp logs show the out of office being sent to the smart host successfully or not?

You could temporarily setup a new send connector that just goes directly out (no smart host, just use DNS/MX). Sent that as the primary send connector, run some tests and then set it back again. If Out of Office works fine on that then I'd be looking at the smart host as being the issue in which case you'd need to contact them about it.
0
 
LVL 4

Author Comment

by:Vlastimil Sopuch
Comment Utility
Yes, you're correct. The internal OoO works fine.

Hmmm, just did a test with the smart host off, using the DNS MX records and it fails with exactly the same error: "550 5.5.0. Sender Domain is empty" ..when I do Exchange message tracking for automatic reply.
- I haven't restarted the Exchange Transport service" before the test. Might need to re-test after hours again.
0
 
LVL 13

Assisted Solution

by:Andy M
Andy M earned 500 total points
Comment Utility
Came across this article which may be of use - same issue with Exchange 2007 and Fortinet systems (plus does mention same thing on Exchange 2010).

https://forum.fortinet.com/tm.aspx?m=81879

Yeah, if you make any changes to send/receive connectors it is always worth restarting the Exchange transport service as well to ensure the changes are correctly applied.
0
 
LVL 4

Author Comment

by:Vlastimil Sopuch
Comment Utility
I came across similar article, but can you tell which policy to edit? FortiMail_PolicyThanks a lot!
0
Why do Marketing keep bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

 
LVL 13

Expert Comment

by:Andy M
Comment Utility
I would guess it would be 16 and 17. Unfortunately I don't have a great deal of experience specifically with fortinet applications so not much use in actually changing the settings but those two seems to be rules applying to external systems.
0
 
LVL 4

Author Comment

by:Vlastimil Sopuch
Comment Utility
I'm attaching all 4 policies currently created for review. If someone with more networking background could suggest what needs to be changed please. Or should a new policy be created? Thanks Fortimail_Policy.png
0
 
LVL 4

Accepted Solution

by:
Vlastimil Sopuch earned 0 total points
Comment Utility
The fix was in Fortimail appliance / Policy / Policies - creating a new policy for the customer and unchecking the "Reject empty domains" under "Unauthenticated Session Settings".
0
 
LVL 4

Author Comment

by:Vlastimil Sopuch
Comment Utility
Thank you Andy M for your help with this! Appreciated.
0
 
LVL 4

Author Closing Comment

by:Vlastimil Sopuch
Comment Utility
The issue was resolved by further testing myself at the end.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now