Jawloms Posted April 5, 2018 Posted April 5, 2018 Morning, I have just changed to schoolsbroadband (late yesterday) and am after some help with my mail relay. When I asked what the mail relay server address was I got told that they wouldn't recommend I use it as they get blacklisted occasionally(!), but also told what it was. I used to get my broadband via my LA, who also were my mail relay. Now I've come away from them I have to change it. I changed the "Route mail through the following smart hosts" in my send connector (Exchange 2010 SP3) to the schoolsbroadband address and now nothing will send. It bounces back saying; Delivery has failed to these recipients or groups: Sean Richards ([email protected]) Your message wasn't delivered due to a permission or security issue. It may have been rejected by a moderator, the address may only accept e-mail from certain senders, or another restriction may be preventing delivery. The following organisation rejected your message: smtp.livemail.co.uk. Diagnostic information for administrators: Generating server: DHS-EXCHANGE.debenham-cc3.internal [email protected] smtp.livemail.co.uk #553 5.7.1 : Sender address rejected: not logged in ## What do I do? Also - We have Office 365 accounts, but don't use them for email. Do they have a mail relay I could use instead? I've done nothing with the incoming email yet as I need to speak to my LA to update this. Thank you Stuart
mavhc Posted April 5, 2018 Posted April 5, 2018 Do you need to route via another host? Can't you just send directly? Not logged in sounds like it's not using TLS to send email. TBH I'd just move to Office365 and not use an internal exchange server, it's not hard to migrate.
Meldrew Posted April 5, 2018 Posted April 5, 2018 I'm not the biggest expert in this, but I'd say you have 2 options. 1) Setup your send connector to send directly without a smart host (you may need to create a new send connector from memory) or 2) use Microsoft's mail server - that's how we do this - even though we have on premises mailboxes, all mail goes out through O365 and back in via 365 as this was a massive help in spam prevention and ensuring that outgoing mail wasn't itself marked as spam and blocked (which I'm assuming is the problem with your quoted email above). HTH, Meldrew
Jawloms Posted April 5, 2018 Author Posted April 5, 2018 2) use Microsoft's mail server - that's how we do this - even though we have on premises mailboxes, all mail goes out through O365 and back in via 365 as this was a massive help in spam prevention and ensuring that outgoing mail wasn't itself marked as spam and blocked (which I'm assuming is the problem with your quoted email above). HTH, Meldrew Thanks for this Meldrew. I'm not the biggest expert either. Option 2 looks good, how do I do it? Presumably I need to ask the LA to change my MX record? What about settings for outgoing mail on the server? Stuart
sister_annex Posted April 5, 2018 Posted April 5, 2018 Have you got Exchange Online Protection on your O365 tenant?
Jawloms Posted April 5, 2018 Author Posted April 5, 2018 I'm guessing not as I've barely done anything with Office 365 other than make the accounts sync with my DC. Like I say, we don't use O365 for email so would it be turned on? I've just had a look around the Exchange Admin Centre and can't see anything obvious.
Meldrew Posted April 5, 2018 Posted April 5, 2018 Thanks for this Meldrew. I'm not the biggest expert either. Option 2 looks good, how do I do it? Presumably I need to ask the LA to change my MX record? What about settings for outgoing mail on the server? Stuart My colleague set all this up for us and took a while to get right to be honest and a huge amount of research. The difficulty is while you're getting all the details right, mail flow is quite possibly disturbed, bouncing back, etc. Your users need to know that mail will be a bit flakey for a while. From memory, you need to ensure you have your AD sync'ing with office 365, so when mail arrives at Microsoft, O365 knows how to route it. Something to do with -onmicrosoft.com email aliases. For MX records, yep, this will need to be changed and you'll need an SPF record too (so that recipients trust that your domain isn't a source of spam), but you just use the one that Microsoft provides I think. If there's anyone else here that can advise on the details I'd pick their brains, but you'll probably need to spend a couple of days at least reading up on how it all works. Sorry this isn't a great deal of help! Meldrew. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now