Jump to content

Hybrid O365 with Exchange 2010 - not recieving external emails


Recommended Posts

Posted

Hi,

 

I'm performing a hybrid migration to O365 with an Exchange 2010 server. So far everything has gone well (Azure Diresync, Hybrid configuration manager etc)

 

I've just had our ISP add the DNS records specified on the o365 domain verification page so that we can route our email through EOP but now I can't send emails to an external address

 

I can send / receive internally

I can send an email to an external address

I don't receive any external emails (external senders do not get the email bounced back)

 

I would assume this has something to do with the new MX record... I left the old one that points to our Exchange - could this be the issue?

Posted

just tried to contact Microsoft Support through 365 portal , did a trace on one of the sent emails and got this response:

 

We've found an issue

 

 

Sorry, Office 365 received the message that you specified, but it hasn't been delivered to the recipient ([email protected]) yet. Unfortunately, it has been delayed. We're working on delivering it.

 

 

 

This is the last record we have for the message: In process

Posted

Hmmm, looking at the details of one of the pending emails it says:

 

"450 4.4.101 Proxy session setup failed on Frontend with ‘441 4.4.1 Error encountered while communicating with primary target IP address: “Failed to connect. Winsock error code: 10061, Win32 error code: 10061.” Attempted failover to alternate host, but that did not succeed. Either there are no alternate hosts, or delivery failed to all alternate hosts. "

 

Which looks like a firewall issue...

Posted

Hopefully someone here can help me understand this a bit better.

 

If I log into my O365 admin panel and try to validate the inward bound connector that points to my on-site Exchange server I get the error detailed in the post above. Searching the web for details on that error; everything is very specific - port 25 is blocked for inbound SMTP traffic. I've talked to Microsoft tech support and they say the same.

 

We get our broadband from the LEA who work Mon-Fri 9-5 and we don't have access to this kind of thing, they have to sort it out for us. I won't be able to resolve this issue until Monday morning so I'm going to lose some emails (after 48 hrs non delivered emails are deleted/bounced back)

 

Before Monday morning I'd like to get on top of this - is there anyway I can confirm that the above SMTP / Port 25 scenario is absolutely true? Could it be anything else? I don't have any issue sending or receiving emails or send ing emails to external addresses - I just cannot receive emails sent from external addresses.

 

I'm abit confused by it as I lack don't really understand how email traffic works. Our Exchange server has worked fine for years so all SMTP traffic must have been coming through on port 25 or an alternative port... Is this info embedded in the send / receive connectors or is it controlled directly by the firewall?

 

Hope someone can shed some light as I need to get this put to bed on Monday morning

Posted

Now it's just getting ... weird. I have found ONE user who CAN receive ALL external mail!!

 

How can the inward bound connector fail validation (from the o365 admin portal) but one user doesn't have any issues?

 

I've just been on the phone to a microsoft tech guy, he had a look at one user where I had applied a license - he told me that this was the issue as licenses shouldn't be applied to users who have their mail box sat on the on-premise server.

 

He was pretty adamant - but it's not the case. I can take an example user with no license applied (I haven't applied licenses to 99.9% of users). Send them a test email from an external account and it will end up stuck in a queue 'pending'

 

This is making my head throb

Posted

I think I've just slowly sent myself mental, which is never good. Partly because you miss the obvious.

 

The user who is receiving external emails is ONLY getting them delivered to their O365 account. Not the on-premise Exchange mailbox (I had created them an o365 account - pre migration, to have a look at)

 

This explains why I couldn't validate the inbound connector in the O365 admin portal AND they were receiving external emails - no mystery (phew)

 

So, either my broadband is blocking SMTP traffic on port 25 or my MX records are incorrect...

 

Does anyone know of any online tools I could use to test which of these might be the issue?

Posted

I'm sure Microsoft had some tools for testing exchange.

Also, is it defo port 25? It's not being encrypted into 465 or 587 is it? Might be ticked for encryption / secure / tls or something like that somewhere.

Chances are the LEA is blocking it.

Posted
I'm sure Microsoft had some tools for testing exchange.

Also, is it defo port 25? It's not being encrypted into 465 or 587 is it? Might be ticked for encryption / secure / tls or something like that somewhere.

Chances are the LEA is blocking it.

 

I think it is the LEA blocking SMTP traffic.

 

I was a bit weirded out by the fact that I can send external emails (why is the LEA not blocking outward bound SMTP traffic as well?) but thinking about it, Outward bound traffic sent from our local Exchange mailbox isn't being pushed through O365/EOP - only inbound traffic. That would make some kind of sense.

 

In O365, Admin panel, If I try and validate the connector, it fails. If I look up the error message, most internet posts describe it as a firewall issue (SMTP traffic blocked)

 

I guess I'll have to wait till Monday 9AM to find out!

Posted

I tried to telnet our mail server on port 25 & the operation timed out at the public facing IP address

 

I then tried checking it using a port scanning web site and it came back with the message 'port 25 is closed on this server'

 

So it definitely looks like it's our LEA is blocking the traffic or using an alternative to port 25

 

Hopefully it will get resolved in the morning

Posted

All sorted! Sort of...

 

Our ISP lease their service from RM - the incoming traffic is being blocked by them.

 

They can resolve this but they need to know

(a) what ports need opening

(b) the O365 IP range

 

To do this they charge £140 & if we have to change it again, they will charge us another £140!

Turn around time can be 24hrs+

 

For now the easiest solution for me is to remove the O365 records from DNS so our email is routed as it was originally & I'll have to sort O365 when the school closes for Xmas.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...