Strange email problem
Author
Discussion

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
I have a consistent but strange problem, but I'd better tell you about my email problem instead

I'm running Small Business Server 2000 which includes Exchange 2000. This has been working very happily for the last 2 years, except for the last month or two where one client is not receiving email from us. To be clear this is any person within that company does not receive email from anyone within my company.

The client is a large blue chip company, I have spoken with their MIS department who insist that our email is not hitting their servers. I insist it is leaving our server but where does it go? I'm getting no bounce or failure to deliver messages and am now at a loss. I go on holiday for a week today and really would like to resolve before I go.

Any ideas would be gratefully received....

TIA
Jon

pdV6

16,442 posts

291 months

Friday 11th February 2005
quotequote all
Is the IP of your Exchange server being filtered out by their firewall before traffic even gets to their mail server?

miniman

30,079 posts

292 months

Friday 11th February 2005
quotequote all
From experience with large blue chip companies, particularly those whose IT is subbed out to three-letter-acronym compaines, I would suspect that the mail is getting onto their systems and then disappearing internally somewhere. As you say, I would expect a bounce message if your mail had genuinely not reached any destination.

Have you tried switching on delivery and read receipt for the mail? This will tell you if it arrives somewhere (although not necessarily whether it has arrived at its intended destination)

Plotloss

67,280 posts

300 months

Friday 11th February 2005
quotequote all
Can one trace a route to a particular port at an IP address?

This would show that your ISP and your server can see the destination...

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
miniman said:

Have you tried switching on delivery and read receipt for the mail? This will tell you if it arrives somewhere (although not necessarily whether it has arrived at its intended destination)


If I turn both of these on I get

"This is an automatically generated Delivery Status Notification.

Your message has been successfully relayed to the following recipients, but the requested delivery status notifications may not be generated by the destination."

I also get the same message if I spell the recipient's name wrong
I do get a DNS lookup error if I spell the domain wrong though!

Plotloss

67,280 posts

300 months

Friday 11th February 2005
quotequote all
Thats telling you that its hit the mail server, I think.

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
pdV6 said:
Is the IP of your Exchange server being filtered out by their firewall before traffic even gets to their mail server?


I'll ask them. (not expecting to get a particularly helpful reply though )

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
Plotloss said:
Thats telling you that its hit the mail server, I think.


thats what I think, but they insist it's not.... Right back on the

Tripps

5,814 posts

302 months

Friday 11th February 2005
quotequote all
Saw something similar on a colleague's SBS server earlier this week.

Open up Exchange Manager and look for the outbound queue, somewhere under the server (don't have it in front of me), we had a huge outbound queue that would not shift but looked like it had gone.

Clearing the DNS cache did the trick in the end.

Tripps

5,814 posts

302 months

Friday 11th February 2005
quotequote all
jonnie5 said:
Your message has been successfully relayed to the following recipients, but the requested delivery status notifications may not be generated by the destination.
That's a Microsoft message, which could be from your outbound SMTP server, or perhaps something en-route to your client...

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
Tripps said:
Saw something similar on a colleague's SBS server earlier this week.

Open up Exchange Manager and look for the outbound queue, somewhere under the server (don't have it in front of me), we had a huge outbound queue that would not shift but looked like it had gone.

Clearing the DNS cache did the trick in the end.


Had a look at these two, the outbound queues are all empty and I have cleared DNS cache. I still get same message back which could well be locally produced .

Still trying to get their MIS department on the to confirm that they have not block my IP address.

Tripps

5,814 posts

302 months

Friday 11th February 2005
quotequote all
If you send via SMTP you could try logging on manually using a decent telnet cliet, port 25 as I recall.

While you're there if its unautenticated feel free to send naughty messages

_DeeJay_

5,057 posts

284 months

Friday 11th February 2005
quotequote all
jonnie5 said:

Tripps said:
Saw something similar on a colleague's SBS server earlier this week.

Open up Exchange Manager and look for the outbound queue, somewhere under the server (don't have it in front of me), we had a huge outbound queue that would not shift but looked like it had gone.

Clearing the DNS cache did the trick in the end.



Had a look at these two, the outbound queues are all empty and I have cleared DNS cache. I still get same message back which could well be locally produced .

Still trying to get their MIS department on the to confirm that they have not block my IP address.


There's a million and 1 answers to this.
However, the message you got says that the message was relayed from your server to the next hop.

Do you forward to another relay or deliver directly?
If direct, lookup the MX records for their domain and see if they accept directly (some use external spam/virus solutions).

If it's hitting their servers then I'd look into the possibility of your servers being classed as spam (and therefore not hitting their internal mail servers). You're not on any of the nasty commerical lists are you?

It'd also be wise to enable message tracking on that site and you'll be able to see which host the message was actually delivered to, if in doubt.

D

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
I've now had a decent with them and a couple of their guys are looking into it from their end now, waiting for a call back .....

Thanks for your help so far guys.
Jon

_DeeJay_

5,057 posts

284 months

Friday 11th February 2005
quotequote all
jonnie5 said:
I've now had a decent with them and a couple of their guys are looking into it from their end now, waiting for a call back .....

Thanks for your help so far guys.
Jon


In the meantime you might want to enable message tracking and that'll help them trace the message through their relays too (and it's always a god send in Exchange when you get users claiming mail went missing and you have to prove it didn't).

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
_DeeJay_ said:

In the meantime you might want to enable message tracking and that'll help them trace the message through their relays too (and it's always a god send in Exchange when you get users claiming mail went missing and you have to prove it didn't).


I have message tracking on but, unless I'm reading it incorrectly (which is highly possible!), it appears that every message log stops when the message is passed to AVG before leaving our server (AVG is the Virus protection we have in place on the Exchange server).

However, it is highly likely that I'm not using this correctly as I am at the very edges of my knowledge here

On the phone to them now ......

_DeeJay_

5,057 posts

284 months

Friday 11th February 2005
quotequote all
hmmm, that's probably true. Message Tracking just checks the logs that are stored in a share on the machine.

If Exchange delivers mail to the AV engine using SMTP (or something other than the VAPI) then the chances are you won't be able to see where it went (which is a shame).

The other thing is that your relay notification may just be to the Virus software (if it send using SMTP) so the messages may never have left the system (though they have left exchange!).

Darren.

edited to add: AVG looks like it's at the SMTP level, so the chances are that software delivers the email, not exchange. Is there anywhere in that product you can check to make sure it wasn't actually held/dropped?).


>> Edited by _DeeJay_ on Friday 11th February 16:03

jonnie5

Original Poster:

716 posts

283 months

Friday 11th February 2005
quotequote all
_DeeJay_ said:
hmmm, that's probably true. Message Tracking just checks the logs that are stored in a share on the machine.

If Exchange delivers mail to the AV engine using SMTP (or something other than the VAPI) then the chances are you won't be able to see where it went (which is a shame).

The other thing is that your relay notification may just be to the Virus software (if it send using SMTP) so the messages may never have left the system (though they have left exchange!).

Darren.

edited to add: AVG looks like it's at the SMTP level, so the chances are that software delivers the email, not exchange. Is there anywhere in that product you can check to make sure it wasn't actually held/dropped?).


>> Edited by _DeeJay_ on Friday 11th February 16:03


Cheers Darren, I'll look into this - it maybe that we've recieved virus from that domain and it's blocking mail back to them , or maybe I'm talkin Bollox...

The other route I'm following at the moment is it appears that a reverse DNS lookup on our domain is not returning what is expected and may casue the client server to reject our mail. ISP informed and will hopefully be rectified within 2 hours - 2 days !!

In any event it looks as if I'm not going to fix this before I go on holiday, so I'm off to the pub!

Many thanks for your help
Jon

_DeeJay_

5,057 posts

284 months

Friday 11th February 2005
quotequote all
jonnie5 said:

_DeeJay_ said:
hmmm, that's probably true. Message Tracking just checks the logs that are stored in a share on the machine.

If Exchange delivers mail to the AV engine using SMTP (or something other than the VAPI) then the chances are you won't be able to see where it went (which is a shame).

The other thing is that your relay notification may just be to the Virus software (if it send using SMTP) so the messages may never have left the system (though they have left exchange!).

Darren.

edited to add: AVG looks like it's at the SMTP level, so the chances are that software delivers the email, not exchange. Is there anywhere in that product you can check to make sure it wasn't actually held/dropped?).


>> Edited by _DeeJay_ on Friday 11th February 16:03



Cheers Darren, I'll look into this - it maybe that we've recieved virus from that domain and it's blocking mail back to them , or maybe I'm talkin Bollox...

The other route I'm following at the moment is it appears that a reverse DNS lookup on our domain is not returning what is expected and may casue the client server to reject our mail. ISP informed and will hopefully be rectified within 2 hours - 2 days !!

In any event it looks as if I'm not going to fix this before I go on holiday, so I'm off to the pub!

Many thanks for your help
Jon



I'd place bets on reverse lookup (I've no idea why people still do that).

If you can post/email me with the recipients domain name, it's easily tested....

jonnie5

Original Poster:

716 posts

283 months

Friday 11th March 2005
quotequote all
An update on this one....

It appears that the problem was two-fold, firstly the reverse DNS lookup not working was causing an issue. Secondly, it appears that the virus software I'm running on the exchange server was causing a bit of interference with the outgoing mail, changed a few settings and that sorted that.

it's just strange how just one client has had these problems....