Jump to content

Recommended Posts

Posted

Hello all,

I am planning to move to GMail split email delivery on Friday (MX records in place to be moved and routing to onsite exchange booked). I paid for a Google partner to write me up a guide so wasn't worried about it, however now its close (and still in time to reverse it) I thought about the route mail will take and figured there is nothing in place for my exchange to know who is onsite and who is not.

 

To confirm, this is how I see it working...

 

incoming mail -MX record sends to gmail - deliverers if gmail box found - if no gmail box found, routes mail to onsite exchange (this is all in place and ready to go, happy with this part)

 

My problem comes when someone onsite sends mail to a group where some are gmail and some are onsite. How will I tell it where to route the mail (exchange 2013)?

 

I looked it up and am more confused than I was before as there seem so many conflicting ways to do it and am struggling to find a clear guide on what to do and what box to put it in.

 

1: Do I setup a send connector to google, disable my previous send connector and change exchange to an internal relay (under accepted domains).

2: Do I go down the alias setup route and if so whats the best way?

3: Short term, as I only plan to move myself and the other two techs over to start with, I could setup a rule to push mail sent to us to our test gmail domain to at least have it get to us for now but need the long term figured out. Want to move my students over this summer.

4: Other?

 

Does anyone have a clear guide to what I need to setup. There is still time to get this all in place and excited to do so. Annoyed this has been left out the guide I paid for but at least I have caught it early enough to sort it out.

 

If anyone knows what I need to do or can point me to a clear guide I would be very appreciative.

 

Thank you

  • Thanks 1
Posted

I think you will need a connector from local exchange to gmail otherwise mailboxes moved over wont get email from local. Just ensure the mailbox doesnt exist on both systems as the way I basically understand it is if local exchange doesnt find a mailbox for an address it sends it down the connector but if it exists locally it will go there. When you move your mailbox over rename your old mailbox on exchange so you can easily move back if you want and things bork. Set your MX records to have a pretty short expiry time as well until you are happy everything is working otherwise it will be borked until it expires if you have to move everything back to pointing to local exchange. Once everything is working you can increase the TTL then though after a few days.

 

Groups should follow that logic if I recall, so if its a local exchange group and it has accounts not on local exchange it will route to gmail via your connector there and visa-versa although I have not had to deal with that sort of split myself.

I have used alias's in the past where basically we set up a subdomain of gmail.{domain}.co.uk with the gmail mx records and created an alias and a distro group for a user. Aka j.smith@{domain}.co.uk was a dist list which had the alias I created added to it of j.smith@gmail.{domain} and mail flowed but that was a system where they were going office 365 from gmail but not all of gmail was moving across so mail routed into office 365 first and would connector to the gmail setup.

There is also a setting you need to change on gmail to whitelist your local exchange ip as a sender just in case spam filtering gets a bit annoyed after the move.

 

I did all this a while ago so sadly things are a bit foggy.

  • Thanks 1
Posted

Thank you for your help and certainly moved me in the right direction. I have the mail relay via Google working now and is my only send connector enabled.

 

The problem I appear to be having now is Exchange still wont route the mail externally. I changed the test mailbox name and even removed it together (ensuring to put the address back in AD) however I just get a mailbox not found error sent from the internal server rather than attempting to send down the connector to Google.

 

Does anyone have a thought on this please?

Posted
Change your remote domains for your email domain from authoritative to internal relay in exchange if I recall. Relay I think sends anything that doesnt exist locally to the connector where as authoritative will send a mailbox not found error.
Posted

its odd... i have done that however its still not passing it externally. I get a mailbox not found error generated from onsite.

 

I'm going to leave the test mailbox disabled overnight and see if the overnight maintenance will take it's toll and tidy things up (always the optimist!)

 

Thank you for your help on this and if anyone else has something to add I would love to hear it.

Posted
Try emailing a fresh test mailbox that has only existed on Google apps and see if it routes. I will have think of any other tweaks we had to do as well.
  • Thanks 1
Posted

Just emailed a new account and got a response from the external connector (gmail routing not live until Friday but I’m happy it was sent externally) so it just seems to be having a hard time forgetting where the mailbox is.

 

Will ponder further.

Posted
Just to update, still no luck. The domain is definitely set as an internal relay but just won't push mail that way if there is no mailbox found. Such a pain and seems to be a common issue people have.
Posted

OK.... have been trying various things all day and still nowhere nearer. My current plan is now to keep the MX change in place but disable gmail for me and anyone else we had planned so at least I can carry on testing. I will no doubt look down the alias route and see if I can get that working but at least I can do it at leisure.

 

Thanks for trying. :)

Posted

If the domain is internal relay, then it absoloutley should ship it elsewhere (up your custom connector) if it doesn't exist. The only issue I've seen with that is if you've got an edgeserver which by default will take the hump and send that email back into exchange and NDR with a loop.

 

Could you add other domains to your route to google and see if traffic goes down that?

Posted

Right so basically if you email a mailbox that has only existed on Gmail from internal exchange the mail is delivered but if its a renamed/has existed on exchange account you get an NDR?

I am starting to think its a maintenance task on exchange 2013, if I recall things like GAL updates are only ran once a week on 2013 and it can cause all sorts of weird issues but its been a while since I got hands on with 2013. I can remember GAL updates causing issues for us when we renamed accounts as well and I *think* microsoft changed future versions to run some of the tasks more often to mitigate it.

I would see if you can manually run some of the tasks and see if that allows the mail to flow through.

  • Thanks 1
Posted

Its all got a little confusing and the tests have come out inconclusive...

 

No Edge server, just Exchange 2013 going straight out.

 

Firstly, new accounts made in google do not receive email (Even after adding SMTP:emailaddresshere to the proxy addresses value) however that can be a problem for another day.

 

I successfully updates the GAL and updated Outlook's copy and then got the text "we won't be able to deliver this message because the email address is no longer valid" above the address bar however.... after 15 minutes, 2 messages arrived correctly in GMail. I do not believe I have changed anything else and tried again but now mail is not being delivered with no bounceback. As per the new account I made for testing, I have had to add SMTP:emailaddress into the proxy addresses value as removing the mailbox clears any trace of email for the account.

 

I'm so confused and if anything, further away from being able to make this work. It burns that I can't get it to do this as I know its something simple I'm not doing but just cant see what that is after a day online looking. Obviously you can tell I have never had to play with Exchange too extensively before so this is trial by fire!

 

Thanks as always and know I'm clutching at straws now but would love any other input.

Posted (edited)

Firstly, use OWA for this type of troubleshooting, there's no appreciable delay in GAL updating to avoid false positives.

 

It's not in the nature of email to disapear into the ether. It's either going to be looping and fail soon, or stuck in a spam bin somwhere. How are your SPF settings, and have you looked at Exchange tracking logs?

 

Also, if you need a target to check setup chaplin.me.uk routing to chaplin-me-uk.mail.protection.outlook.com then email colin at chaplin dot me do uk

 

IF it arives in O365 directly your custom route in this case works :-)

Edited by chaplic
  • Thanks 1
Posted

I have had messages from this morning eventually get back to me :)

 

Just had a partial success, found the following powershell... Enable-RemoteMailbox "mailbox name" -RemoteRoutingAddress "email address allias i.e. test-google-a.com"

 

Now I can send mail to the gmail account and although not as easy as I was expecting, I can make do with scripting this to work as migrations take place...

 

Saying that, email now isnt working from gmail into exchange but until I get the bounceback I wont know why :(

 

Thank you all for your help and patience. No doubt I will have other posts related to GMail in the following days/weeks but at least this gives me something to go on and get at least me and my techs onto gmail (once I figure why I cant send back to onsite exchange!).

Posted
what you've discovered is a mail enabled user with forwarding setup, which will work and means that object is shown in the GAL, but won't get round the basic issue and also mean both sides needs admin work for every email address change.
Posted

just to say thanks to everyone who helped. Things aren't working 100% however very much making progress. Part of the problem was it turned out my ISP did not update the MX records correctly which caused a lot of these funny delivery patterns.

Anyway I still have some questions but have time on my side now I can test accounts at leisure.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...