Avatar of sf1elds
sf1elds
Flag for Barbados asked on

Exchange mail not connecting on mobile

Exchange mail not connecting on mobile device (iPhone or Android). Trying to configure mail on my phone but it won’t connect. I’ve selected ‘Exchange’ as the provider.

Server - mail.domain.com
Domain - domainname.com
Username- firstinitial + lastname
ExchangeMobile

Avatar of undefined
Last Comment
sf1elds

8/22/2022 - Mon
Alan

Does mail.domain.com resolve to your external IP?  If not, then you need to set that up in your public DNS

Have you forwarded port 443 from the external (router) to the internal IP of your exchange server? - If not, then you need to do that.

Have you setup AutoDiscover?  If not, you should set that up:

https://www.howto-outlook.com/howto/autodiscoverconfiguration.htm

Does it work internally?


Alan.
sf1elds

ASKER
Mail.domain.com works fine.

Yes I’ve already forwarded port 443.

Didn’t setup AutoDiscover

Yes it work fine internally.
sf1elds

ASKER
I’m using Exchange Server 2016 and Outlook 2016 on my iPhone
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Jackie Man

https://technet.microsoft.com/en-us/library/bb123679(v=exchg.160).aspx

if you do not set ActiveSync VirtualDirectory, no mobile devices will be able to connect outside the local network.
Hemil Aquino

Hear me out. Firstly you need to configure autodisover in your DNS provider followed by an SRV. So follow my instruction and that will work, assuming you have access to OWA and ECp from the outside.

1- Login to your DNS provider, either godaddy or no-ip.
2- Add an A record called Autodiscover mapped to your public address or @ host.
3- Add an SRV record give a name, domain name of your email, such as: mail.domain.com
4- Is gonna ask you for this option weight=0 and height=0
5- Protocol _tcp
6- Service _autodiscover

After that being in placed, wait half an hour or an hour until the propagation takes place.
Then go to your phone and add an exchange account. Type your username and password and automatically your phone will get all the server configuration without user interaction.

Cheers,
sf1elds

ASKER
Ok so I'm trying to setup the SRV record.

These are the fields I'm required to fill on GoDaddy:-

Service _autodiscover
Protocol _tcp
Name (not clear on what name is required here)
Target mail.domain.com
Priority ????
Weight 0
Port ????
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Hemil Aquino

Name: whatever you want to identify your SRV record.
Priority 0
Port 443
sf1elds

ASKER
Ok cool that's what I had. So let's wait an hour to see what happens.

Thanks
sf1elds

ASKER
It's been 2 hours and still no luck. I'm not able to connect my phone.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Hemil Aquino

Did you configure the authentication using UPN?
Otherwise it won't work. You will have to add the conf manually.
sf1elds

ASKER
explain.

do you mean entering the username as - domain/username ????
sf1elds

ASKER
username - username@domain.com
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Hemil Aquino

You can't use that.
You have to use user@domain.com

If you use domain/user then you have to add all the settings manually.

Such as:

Username password
Domain.
Server
Etc
sf1elds

ASKER
tried that as well.

no luck
Hemil Aquino

I think you need to test the exchange connectivity.
I don't know your configuration.

The way I have told you it should work.
Make sure you have configure well all the virtual directories
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
sf1elds

ASKER
I'll take a look at the virtual directories, but for right now I'm totally lost.....
William Fulks

Do you have SSL turned on?

The URL for your mail server is probably (or should be) https://mail.domain.com
William Fulks

Also, check your domain at www.mxtoolbox.com and see what it reports. You can do some testing there, too.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
SSL is turned on.
https://mail.domain.com/owa works fine.
Virtual Directories are all configured correctly.
William Fulks

What exactly is the error that it gives you?
sf1elds

ASKER
It says UNABLE TO LOG IN

Please check your email address and password and try again.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
William Fulks

So it's connecting but not authenticating. Have you checked to make sure your password is good and the account hasn't gotten locked by all these login attempts? Try resetting your password and see if that works.
William Fulks

Also check Exchange and make sure that OWA is enable for your account - https://technet.microsoft.com/en-us/library/bb124124(v=exchg.150).aspx
Jackie Man

Are you using self-signed SSL cert or wildcard SSL cert for your Exchange server?

You need to use UCC cert.

https://hk.godaddy.com/en/help/what-is-a-multiple-domain-ucc-ssl-certificate-3908
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
The password is correct.

If I use https://mail.domain.com/owa with the same password it works.
sf1elds

ASKER
wildcard SSL cert
sf1elds

ASKER
I just tried using the mail app on my iPhone and I got the following:-

Cannot Verify Server Identity
The Identity of "autodiscover.domain.com" cannot be verified by settings.
Your help has saved me hundreds of hours of internet surfing.
fblack61
Hemil Aquino

I believe you didnt buy a san certificate.

you have a domain certificate.

IN your outlook, do you have any certificate pop ups?

Something like the certificate dont match?
Jackie Man

Agreed.

Unless your mobile phones are outdated which you can ignore the cert, you need a UCC cert for your Exchange server.

https://social.technet.microsoft.com/Forums/lync/en-US/dcd20afc-98fd-4cd0-a4f4-526666d0a8fe/exchange-2010-why-do-i-need-to-use-a-ucc-certificate?forum=exchangesvrdeploylegacy
sf1elds

ASKER
Something like the certificate dont match?

yes
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
I get a certificate error on the desktops but I just ignore and continue
Jackie Man

What mobile device (iPhone or Android) you have tried to connect?
Hemil Aquino

So I know how to fix your problem.

Beforehand I have to ask you a question. Did you buy a san certificate?
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Jackie Man

If your mobile devices are running iOS 10 or above or Android OS 7.0 or above, you cannot ignore the cert.
sf1elds

ASKER
Tried both iPhone and Android.
Did NOT buy a SAN Certificate.
Jackie Man

"Beforehand I have to ask you a question. Did you buy a san certificate?"

Already answered that it is a wildcard SSL cert.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
I'm running the latest IOS on my iPhone and Android
Hemil Aquino

Get a multi domain certificate.

This is what exchange needs on the certificate to work

Autodiscover.domain.com
mail.domain.com

Once you have added those domain in a multi domain certificate then you will be having the pop up error.
Go to namecheap.com and buy a three years one. you will have two slots that will be good enough to fix your issue.
Jackie Man

Agreed. No workarounds without a SAN (UCC) cert.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
sf1elds

ASKER
Ok. Let me go get that certificate and get back to you.
sf1elds

ASKER
Would it be fine going to namecheap.com for the certificate and my domain is at Godaddy?

I'm seeing Multi-Domain SSL (3 Domains Included) for $89.88/Yr Is that the one?
Jackie Man

It will be cheaper if you buy the cert from Godaddy.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Hemil Aquino

Yes, that's good.

Jackie Man: Godaddy will rip him off, but he can call and find out
sf1elds

ASKER
Understood.

It's just that all our domains are already with godaddy. It makes management easier.

Seems like we also have a UCC SSL Certificate with godaddy protecting another domain name
sf1elds

ASKER
I've finally installed the certificate this morning. Still no luck with my mobile phone.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Hemil Aquino

did you check your server connectivity analizer? https://testconnectivity.microsoft.com/

Also what does the phone says?
sf1elds

ASKER
The phone says my username or password is incorrect.
Hemil Aquino

Can you reset your password, make sure you have the correct username, also make sure you are login in with the right option.

Are you using UPN, or domain\user?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
domain\user
sf1elds

ASKER
My password works with the OWA
Hemil Aquino

change the way you login with UPN
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
sf1elds

ASKER
change the way I login?
Alan

Hi,

If you have the right certificate, try logging in as:

username@example.com


Alan.
sf1elds

ASKER
I've tried that.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Hemil Aquino

Yes,

Like right now you are login like this Domain\User.
If you want your phone to take the settings automatically you need a setup like this: User@domain.com

You can login to ECP on the exchange, Servers> Virtual Directory, OWA option and select authentication.
Hemil Aquino

can you log in in your OWA with email and password instead of username and password?
sf1elds

ASKER
No I cannot log in in my OWA with email and password instead of username and password?
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Hemil Aquino

Did you went to your virtual directory and change to UPN? becuase if you didn't it's not going to work.
Also what UPN you see in the exchange when you create a user?

Do you see @domain.com OR @domain.local?
sf1elds

ASKER
New use gets @domain.com
Hemil Aquino

perfect, now go to domain and trust in active directory
and see if you have the same UPN in there.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
I see domain.local
Hemil Aquino

add the domain.com
That's the reason is not working.
sf1elds

ASKER
Ok I may need to read up on how to do this first.
Your help has saved me hundreds of hours of internet surfing.
fblack61
Hemil Aquino

just go to domain and trust, right click in active directory domain and trust then add the UPN and save it.
sf1elds

ASKER
Ok I'm just doomed. Still no luck
Hemil Aquino

what are you mean? did you added the UPN on the active directory domain and trust? domain.com?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
I did
Alan

Sometimes with Exchange, you have to wait a while - maybe a couple of hours, for setttings to take effect, or, if feasible, restart Exchange (or reboot the server) but normally that is difficult in the middle of the day.

Alan.
ASKER CERTIFIED SOLUTION
Hemil Aquino

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
sf1elds

ASKER
You were right on the money. Thanks a mil. I was just a bit flustered.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes