themightymrp Posted July 2, 2013 Posted July 2, 2013 This might sound simple, and indeed it appears to be, but I am having trouble redirecting emails to my new Office 365 account. Our schools old email provider supplied us with Exchange based emails which I could access either via OWA or full Outlook. In my old email I have deleted all of my pre-existing rules (no longer needed) and created one single all-encompassing rule which should redirect all incoming email to my new O365 account. However, it is only working from email sent from our old email addresses, any external-to-company emails are not being redirected at all. I can find no errors and nothing being blocked in the O365 filtering. Am I missing something obvious - like this is expected behaviour? If I modify the rule to Forward instead of Redirect it works - but the downside is I can no longer see the original senders email address to be able to reply to them!. Any clues???
MicrodigitUK Posted July 2, 2013 Posted July 2, 2013 The email will be rejected by Microsofts servers because it's not coming from the original senders servers or an accepted relay server. Security or you could pretend to be any email address. But mail from your old server with the old email address will get through because it is an excepted server to be sending from that particular email address. What you need to do is add the IP address of your old exchange server to the list of excepted mail relay servers allowed to relay all mail to your 365 setup. This I think is done as an admin in Forefront Online Protection for Exchange (FOPE) as part of your 365 setup. 1
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 That sounds like it might be it - but how the bleep do I get into the FOPE admin centre???? Also, does anybody know where I set this once I'm in?
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 OK, its no longer FOPE but EOP. I have gone under the Exchange Admin Center --> Protection -- Connection Filter and added the single public facing IP address of our old mail server. It still isn't working Am I in the right place? I need a 365 guru to help!!!!! @jamesbmarshall -- thoughts?
IrritableTech Posted July 3, 2013 Posted July 3, 2013 Knowing we're using the same LEA system @themightymrp. Which IP are you putting into your connection filter? Our email is forwarding quite happily to google apps from the IP 82.203.3.254.
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 I have been given 82.203.2.9 - I will try yours! Cheers
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 Nope - not working Have you got your emails set to Redirect all incoming messages to your old system to go to your new Gmail one? I don't even know if this is the correct place to put the IP! I just want any emails going to LEA inbox to redirect to O365 inbox. Simple redirect rule on my account should do that. But any external sender i.e. Hotmail just doesn't get redirected.
IrritableTech Posted July 3, 2013 Posted July 3, 2013 Yep, all incoming messages. The .9 address is the mx servers - for receiving mail. All the test messages I have sent are coming from .254 so it should work. This is unless the original sender uses SPF. At that point, it may bounce to the original sender. Googles advice here is to add your old address to your 'send mail as' addresses, and this will bypass the check. Office365 might have the same?
john Posted July 3, 2013 Posted July 3, 2013 Might be missing something here but why are you not having the mail sent straight to O365?
IrritableTech Posted July 3, 2013 Posted July 3, 2013 I'm afraid @john we haven't filled in all the gaps... We are Leeds schools who have been using our LEA email platform provided by Capita. The Leeds authority is pulling the plug on the Capita contract, and have proposed moving to Office365 - Individual tenancies for individual schools. Unfortunately (unless someone can tell me differently) they are not helping people migrate their inboxes, but letting everyone start again. Those staying with the new LEA provision are unfortunately in exactly the same position as those moving to alternative providers with regards to email. Some schools are jumping more quickly than others and having their LEA email forwarded to their new addresses. Ie. [email protected] forwarding to [email protected] or some such other domain. We hope this will give us enough time to let people know our addresses are changing. I bet its an spf issue @themightymrp after looking into it again. 1
john Posted July 3, 2013 Posted July 3, 2013 Ahh so you were using LEA provided addresses rather than school ones that explains it
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 Might sound like a thick-o here but what is the SPF bit?
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 Oh, and how to you mean add the old address to 'send mail as'? Is that within 365 or is that part of the redirect rule on the LEA mail?
jonnykewell1 Posted July 3, 2013 Posted July 3, 2013 check this phil - Sender Policy Framework - Wikipedia, the free encyclopedia
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 Not entirely sure I follow what that actually does but... This is one of the DNS settings which I asked the LEA to apply to our URL's DNS settings: Is that right?
IrritableTech Posted July 3, 2013 Posted July 3, 2013 The issue is that the LEA servers, when set to redirect, send the email on as if it has come from the original sender. Making it easier to reply to, and looks neat in your new inbox. So email from [email protected] sent to [email protected] is actually sent by LEA.net to [email protected] So when school.uk (in this case office 365) checks who has sent the message it finds it came from the IP of the LEA server. When it checks the DNS record for abc.com, the spf record doesn't mention the LEA servers IP address, so it treats the mail as suspicious. I'm not sure I've explained that very well though. It's good to have an spf record on your domain anyway, but it's the original senders spf records you'd need to update to get this working, which of cause we can't. 1
themightymrp Posted July 3, 2013 Author Posted July 3, 2013 It makes sense what you've said. I found this page : http://community.office365.com/en-us/wikis/exchange/customize-an-spf-record-to-validate-outbound-email-sent-from-your-domain.aspx Do you think if I get them to modify the spf TXT record I asked them to create initially to actually contain the below it might work??: v=spf1 ip4:82.203.2.9 ip4:82.203.3.254 include:spf.protection.outlook.com -all
IrritableTech Posted July 3, 2013 Posted July 3, 2013 Sorry @themightymrp I fairly sure it won't. Its the original senders spf record that needs adapting (or the LEAs) not your school domains.
IrritableTech Posted July 4, 2013 Posted July 4, 2013 Just another thought I had... You've got spare space on your old email account right?
themightymrp Posted July 4, 2013 Author Posted July 4, 2013 Hell yeah! I cleared it all out - downloaded to a PST. I have the full 450Mb (woooo) available. I don't know if its going to be possible to do this. Do you know of any way to forward an email but keep the original senders email address in there for reply purposes?
jamesbmarshall Posted July 4, 2013 Posted July 4, 2013 Just chiming in with my two cents... Rather than trying to configure any fancy forwarding etc. (although still a valid approach), have you looked at connected accounts? Learn About Connected Accounts Users can hook up their old account from their new mailbox; might be quicker/simpler to configure given that this would be a short-term solution regardless?
IrritableTech Posted July 4, 2013 Posted July 4, 2013 Just chiming in with my two cents... Rather than trying to configure any fancy forwarding etc. (although still a valid approach), have you looked at connected accounts? Learn About Connected Accounts Users can hook up their old account from their new mailbox; might be quicker/simpler to configure given that this would be a short-term solution regardless? The perfect solution, however our LEA don't allow pop/imap. It's a security risk they say... Thanks anyway James.
themightymrp Posted July 4, 2013 Author Posted July 4, 2013 Yep, just checked that with their service desk Geez I can't wait until we're shut of them!! USELESS
jamesbmarshall Posted July 4, 2013 Posted July 4, 2013 It's a security risk they say... If it helps build an argument, traffic is secured regardless of which protocol you use with Office 365: Settings for POP and IMAP access - Outlook - Office.com If not, oh well!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now