Outbound Mail Flow (bypass EOP for particular Domain)

We have on-premises Exchange 2007/2013 Servers. And have hosted mail protection (Exchange Online Protection). Side note - 2007 servers being retired soon. Our mail is routed via EOP etc.
One of our members of staff is starting to use a goverment secure mail service. This involves setting up a POP3 account on the users Outlook.
It has to be configured to send over SMTP using SSL.
Getting an error saying the connection encryption type is not supported when doing the send test (receives OK).
Upon checking with the Support for the service, routing mail through Office365 will not work. We need to route the mail directly.
This is probably a newbie question but how do I do that? Do I create a new send connector and define the particular domain in there? would I use my ISPs smart host address?
It's just for sending mail, as I say the POP3 account is receiving OK using the POP3 settings.
Thanks in advance.

We have on-premises Exchange 2007/2013 Servers. And have hosted mail protection (Exchange Online Protection). Side note - 2007 servers being retired soon. Our mail is routed via EOP etc.
One of our members of staff is starting to use a goverment secure mail service. This involves setting up a POP3 account on the users Outlook.
It has to be configured to send over SMTP using SSL.
Getting an error saying the connection encryption type is not supported when doing the send test (receives OK).
Upon checking with the Support for the service, routing mail through Office365 will not work. We need to route the mail directly.
This is probably a newbie question but how do I do that? Do I create a new send connector and define the particular domain in there? would I use my ISPs smart host address?
It's just for sending mail, as I say the POP3 account is receiving OK using the POP3 settings.
Thanks in advance.
Yes, define a send connector for the recipients address SMTP scope. 
You wouldnt need to smarthost necessarily, you could simply set it to use the MX record. 
http://social.technet.microsoft.com/wiki/contents/articles/17842.configuring-domain-security-on-exchange-server-2013.aspx
Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

Similar Messages

  • ADC for Domestic Purchase not flowing in MIRO for particular MIGO Document

    Hello Experts,
        We've a scenario in which we pay ADC to domestic vendor. The procedure we follow is as below:
              1. Condition record for JAOP with 0% rate maintained in FV12.
              2. PO created with JMOP 10%, 2% ECS, 1% SECS & 4% VAT.
              3. During MIGO (also excise invoice capture), AED value is maintained
              4. After J1IEX, at the time of MIRO this ADC along with other duties flows in simulation
        Now in my case, there are number of GR documents for which MIRO is performed, but for particular GR, ADC is not flowing in MIRO and also excise duty is incorrect, it's not flowing from GR.
       So what is the probable solution for this, I've already checked MIGO & excise invoice documents & found to be ok.
    Thanks in advance
            Amit

    Hi,
    Have you maintained material price including AED price??
    If yes then check whether you have maintained JAX1-100% or not?
    I think this should be treated as a dealer purchase as you are maintaining 0% amount for JAOP.
    Regards,
    Piyush

  • Bypassing proxy for certain domains

    i have been advised that i can use an XML tag called <dontProxyFor> to bypass the use of a proxy server for certain host/domains in a URL-based portlet.
    The node is a child node of <proxyInfo>.
    i am using Portal 3.0.9.8.4 on Solaris. i have made the addition to my provider.xml but my portlets still seem to require proxy authentication ...
    is this tag only support in higher versions of Portal ??
    on the other hand, is there no way for us to specify a proxy user/password in the provider XML for URLservices ?

    On 08/07/11 15:36, JackCunha wrote:
    >
    > The browser is not used. There is a program on the workstation which
    > tries to connect to the site online. Tthe ports required are 4282 and
    > port 4280/4285, but I assume I also need to get access and get through
    > the BM proxy at 192.168.1.1, and the program does not support proxies.
    >
    >
    bm proxy is normally only for port 80/443, when using the forward proxy.
    If this program access port 4282 and 4280/4285, then it depends how you
    internet connection is set up. If bm is the default gateway for the
    internal hosts and filters are applied, then you will need a filter
    exception for this ports and enable dynamic nat to allow this traffic to
    reach the internet. So bm proxy is not involved here.
    If bm is not the default gateway, then this program will use the default
    gateway defined on the PC to reach the internet and then is there where
    you have to allow this traffic.

  • Send connector with smart host redirection for particular domain

    Hello,
    We have quite big environment with Ex2007 CCR cluster with 2x CAS/HUB and 2x Edge servers with few accepted authoritative domains for several countries. Currently all mails from these are routed through one send connector.
    We're moving to a different mail filtering service and I wanted to setup one of our domains to send through the new service to get it all setup and working correctly before moving the other domains over to it.
    So i have configured dedicated new custom send connector ( in accordance with techent article: http://technet.microsoft.com/en-us/library/aa998814%28v=exchg.80%29.aspx) for one of our domains let's say contoso.com with priority 1, and in next step i have
    entered smart host ip's and at the end source servers (2x edge servers).
    I have spotted that mail would still not send through my new send connector for those with email addresses with that domain. I turned on verbose logging but still all emails are not going through new connector. I checked that changes were replicated succesfully
    on Edge servers and I restarted  on Cas/Hub machines "EdgeSync" service but still no luck.
    Please help me did I forgot to check/change something?

    Let me be sure I understand how you have your new send connector configured, so I don't give you the wrong information.  You said you configured the new send connector with the contoso.com email domain.  From how you said it, though ("one of
    our domains"), it appears that email domain is one of your internal email domains.  If this is the case, this is why this send connector isn't being used - the send connector will send only to those email domains listed in the address
    space tab.  If I am right, it will never send to any external recipients with an contoso.com email address - those mailboxes are internal.  If you have an external SMTP domain in that list (such as hotmail.com), you should see messages sent to recipients
    on that system through this connector.
    If I am not right in how I read your posting, let me know so we can figure out how to get your send connector working properly.

  • Restricting mails to a particular domain

    Hello,
    I am using JavaMail API and have a small requirement. I have to restrict my outgoing mails to only to a particular domain. I mean the mails that i send should go successfully only if the domain is "[email protected].Even if the users of my application types someother domain like yahoo.com or anything else, the mails shouldn't go. I want to restrict the users to send mails to only our company domain. Is that possible, any method available to set it so?
    Please help.
    Thanks in advance.
    Pradeep

    If you control the mail server you're using, you
    can probably configure it to limit messages to
    your domain.
    There's nothing in JavaMail to help you with this.
    If you can't configure your mail server, you'll have
    to implement the limit in your application.

  • Suddenly can't connect to gmail SMTP for outbound mail

    I have both a MacBook Air and an IMac. Recently, I lost the ability on both machines to send outbound mail. With Apple Care help on my supported machine (the MacBook Air,) we rebuilt my gmail mail account on that machine and was able to reconnect and send outbound mail. (receiving mail was never a problem)
    However, going through all of the same steps on the IMac, it keeps saying :"Gmail (offline) next to Outgoing Mail Server (SMTP) on the account information screen. When I run Connection Doctor, I have a red light next to Gmail SMTP with the message "Trying to log into this SMTP account failed. Verify that the username and password are correct."
    Well, the username and password are correct. I just changed them, and can access Gmail from all of my other devices...MacBook Air, iPhone, IPad.
    What is really odd it that is was working until about 3 weeks ago.
    Any suggestions/ideas? I'm not particularly technical...just find this very frustrating and don't know where to turn.

    Robert Wilkins2 wrote:
    Thanks for your reply Csound. I know that it's not right to solve my own post, but after thinking the problem was solved, I clicked resolved. I wanted to share my "solution" with the community. Sorry about bad form.
    No bad form to worry about, just the reduced attention to your problem that a solved designation causes.
    If I remove my gmail account, I'll be able to get all the emails back when I create my new one - because it's imap?
    Yes, but check 2 things,
    1. That it is setup as Imap (POP is possible but is not the default) and 2 that you have not created any local folders that house mail from the Imap account, if you did then you must export them before removing the account.
    What do you mean by verify both passwords? You mean imap and smtp?
    I assume I should be using the application specific password in my mail settings?
    Thanks,
    Bob
    Imap and SMTP should be the same, but check.

  • Exchange 2013 SMTP Mail Flow from external domains

    I have query related to mail flow for incoming mails from external domains from Internet facing site. There are two sites - Site A & Site B. Both have Exchange 2013 CAS servers in NLB and Exchange 2013 Mailbox in individual DAG - say DAG1 in Site
    A and DAG2 in Site B. Site A is Internet facing site and site B is not Internet facing.
    An incoming Internet mail meant for recipient in Site B will land in Exchange 2013 CAS server in Site A. This CAS Server in Site A will look for the recipient in local Domain Controller and get to know the mailbox database of this recipient is in DAG2 (
    in site B ) Will the FET service in EX2013 CAS in Site A make a SMTP connection with FET service of EX2013 CAS in site B which will then make SMTP connection to EX2013 Mailbox server in Site B which is holding the recipient mailbox Active copy for delivery.
    OR
    EX2013 CAS will send this mail to Ex2013 Mailbox server in site A and the Hub Transport service running in in site A will then make SMTP connection with EX2013 Mailbox server in Site B which is holding the recipient mailbox Active copy
    Need clarification on above
    Thanks
    Parveen

    Hello,
    Come back and mark the replies as answers if they help and unmark them if they provide no help.
    I'm marking the reply as answer as there has been no update for a couple of days.
    If you come back to find it doesn't work for you, please reply to us and unmark the answer.
    Cara Chen
    TechNet Community Support

  • Will MX record work for the incoming mail flow and external mail flow.

    Hello All,
        I have created 2 machines with windows 2008 R2 workgroup and  installed Forefront TMG 2010 
        I am using the VIP for the external adapter for the NLB and going to connect it through the MX record will it work for the incoming mail flow to the Exchange 2010 and external mail flow.
        Is that right what i am doing please suggest. Thanks in Advance!
    Sidharth Guntoji,Messaging Consultant, ITBigBang (P) Ltd Www.ITBigBang.Com | Hire Us for Messaging Consulting

    Hi,
    Based on my experience, the MX record contains the fully qualified domain name of the messaging server that’s responsible for accepting messages for the domain.
    Do you want to configure the TMG server as a secure SMTP relay server? Did you mean that the external DNS server point to TMG’s external IP for the MX rcord and the internal Exchange server is using TMG’s internal IP address as the default gateway? Did you
    install any exchange role on the TMG server?
    I am sorry to say that I am not quite sure of your deployment, I would appreciate it if you can share your network topology and configuration.
    Best regards,
    Susie

  • Can Mail block all incoming mail from a particular domain?

    Can Mail be configured to block all incoming mail from a particular domain? I'd rather it be sent to the bit bucket than sent to a spam folder.

    Yes, go in to your rules and set it up for a folder of your choosing.  Click on the mail menu item then select preferences and then click on rules.

  • How can i block outgoing mails to  particular domain

    I have just set a mac mini with snow leopard server . Configured mail in it . I want to block the outgoing mails to some particular domain or all domains other than my server domain .
    please help

    Hi Fritz:
    Your English is FAR better than my Deutsch (Ich bin ein Wisconsonite).  I can barely ask for the train to Zermatt (one of my favorite places on Earth).
    Anyway, I think I understand your question.  If you mean is there a way to stop the recipient of an E-mail from actually getting it (after you sent it), the answer is no (in Apple's Mail application).  Entourage (a Microsoft application) is a good program.  As I recall (I used Outlook years ago in my corporate world) the Microsoft mail applications have a feature to "un-send" E-mail).  However, I think that only worked if the mail was sent to someone on the same network.  You could not retrieve mail from someone outside your own network.
    Barry

  • How to configure mail for multiple domains

    Hi There:
    I am the only Admin for a Mac Mini Lion Server, I have 3 Domains that I host, the DNS is done separate along with all records.
    I was able to get the Web Sites up and running.
    I need help to set up Separate E-Mail Accounts for each Domain, so each Domain receives it's own mail.
    Will you please give a hand, I am a beginner
    Thank YOU!!! in advance!!!!

    There is no default for those entries. you need to set it up manually by using the custom label.

  • How to bypass from OAM authentication for certain domain

    Hi All,
    We are trying to unprotect certain domain from OAM domain but coudn't. Please help us fix this issue.
    Environement details:
    We have two nodes, one node for OAM_OSSO and another one for OSSO_Portal application.
    OAM server details:
    In this server, oracle application server single sign on(services are HTTP, OC4J, and OID) and OAM. Integrated OAM_OSSO using [ID 979827.1]
    Portal server details:
    In this server, oracle application server single sign on(services are HTTP, OC4J, and OID) and portal weblogic server(portal application) is running. portal weblogic is registered with thier own portal OSSO.
    In OAM, We protected following portal url's
    /sso/auth      
    /pls/orasso/orasso.wwsso_app_admin.ls_login
    portal _OAM integration is working fine.
    Now portal team come with new requirement for customer, application also running in their same portal weblogic server and that portal application domain is alreday registered with Portal OSSO and Portal OSSO page is protected by OAM. the requirement is bypass OAM authentication, and need to authentication against their own portal OSSO+OID.
    Please tell me how to bypass OAM authentication from this scenerio.
    -Sarath

    Hi MD,
    Thanks for your update.
    We are using oracle 10g. Please tell me how Anonymous scheme will help us to get out from this issue.
    Portal Weblogic server registered with portal IDM server and portal IDM server OSSO protected by IDM OAM. So if i tried any of the application which deployed under portal weblogic server will get protected by OAM right. Please correct me if iam wrong.
    In this scenerio we have two OSSO, one in OAM node and another one in portal server. Now portal team come up with new webserver domain for customer, in customer scenerio we want authenticate againt portal OSSO with their own OID rather than using OAM authentication. Here my concern is, customer or employee the portal weblogic server and portal OSSO are common for both user but only difference in webserver domain.
    So if i tried to access customer application, then customer webserver redirect to portal weblogic for open the requested page(note if webgate not in picture). portal weblogic server is register with portal OSSO and its redirect to portal OSSO for authentication but Portal OSSO server integrated with OAM using webgate.
    1. When tried to access customer application ,Portal OSSO server tried to show own sso login page for authentication but Portal OSSO server already integrated with OAM. so portal OSSO server requested to OAM to access portal sso login page not the request of customer page login.
    2. here,portal OSSO login page protected and OAM serve login page for OAM authentication against OAM OID. If i specify anonymous scheme for customer domain then how will work here, portal OSSO requested to OAM to access portal OSSO login page not the customer page or employee page...
    Here OAM authentication will come into picture for all scenario but need bypass for customer login.
    Requirement is when customer trying to access then authentication need to happen in portal OSSO not in OAM. Hope you understand the architecture.Please suggest how.
    -Sarath
    Edited by: 898990 on May 11, 2012 8:22 PM
    Edited by: 898990 on May 11, 2012 8:25 PM

  • Force Cover Flow to use a particular artwork for a tv show?

    I had a mix up with Cover Flow before but that turned out to just be me getting confused with the way it displayed artwork for various series of a tv show. But now it really is taking the ****.
    The scenario is this, I ripped a tv show from a DVD, several series of it. Put the first series in, gave every episode individual artwork, gave it a programme name, unique Episode ID that was incremental and also a episode number, also incremental.
    This seemed to work fine. Every episode was in order, and Cover flow showed the first episode's artwork as the series artwork which is what I thought it was supposed to do.
    I've been trying to put in the second series, did it exactly the same way. Except after quitting iTunes and restarting it, Cover Flow has idiotically decided to display the artwork for one of the other episodes, not the first one of which I have special artwork set for and for. There is no error in the Episode ID incremental numbers or the Series Number or the Episode Numbers, they're all correct, I've done my usual multi-check and delete then re-add. It just seems to like using the artwork for the eleventh episode as opposed to the first.
    So how can I force Cover flow to display a particular artwork for a show? I probably wouldn't mind so much but its choices are reflected on my Apple TV and it just looks a bit crap on that.

    Forget it. Obviously no one knows.

  • Not send mail for external domains

    Hi,
    I have installed OCS 10g(10.1.2) in linux. All components ok, but i not send mail for external domain.
    Att,
    Mesti

    I remember in version 9.0.2 that i configure in SMTP_OUTBOUND the IP of DNS external to send mail for other domains.
    Mesti

  • Mail for vanity domains

    we have some vanity domains, e.g. they are not our main organization, but we still want to receive e-mail at them, for several accounts. what are the best ways to deal with this? our DS has one organization in use, and it's our main domain.
    i could just forward the e-mail, but maybe there's a better solution?
    thanks,
    s7

    Hello:
    First off, I'm thinking you did too much.
    If what you want is to have a few of your existing users accept mail for another domain, all you need to is add
    mailalternateaddress
    OR
    mailequivalentaddress
    Adding both is bad, and will inactivate that mail address.
    Doint the above, AND adding vanity domain stuff will make it worse . . .
    If the server accepted the mails, but didn't deliver 'em anywhere, most likely the messages are still in the queue. Look for message files in your tcp_local channel (most likely, but not the only possibility), where the file name has been changed to ".held". The server does this when it thinks the message will loop, and then requires manual intervention to resolve the problem.
    Look, too, at the Access Log on your LDAP server. Look specifically for the search for that mail address. Check the return for >1 "nentries=". If you get more than one, then that mail address can't work. Mail addresses need to be unique.
    You can also test the mta, to see what it whould do with a mail:
    imsimta test -rewrite test_mail_address@domain
    If you'd like to explain more fully what it is you're trying to achieve, perhaps i can help you get there with a minimum of problems. It's also very worthwhile including
    imsimta version
    output when you ask questions, as there are over 25 different versions of 5.2, each with different issues. . . .

Maybe you are looking for

  • How can I get Numbers 3.2 to recognise 1e-5 as scientific notation?

    I just changed from Numbers '09 (2.3) to Number 3.2 on Mavericks (OS X 10.9.3) and the new version doesn't seem to recognise "e" or "E" as scientific notation. When I set the cell format to scientific and type "0.0015", Numbers returns "1.5×10^-03".

  • I have a nano 5th generation and buttons do not work but click wheel does

    My buttons often do not work. Until today, if I toggled the move button I could get it to work after 3-4 minutes of trying. I restored the  nano 1 hour ago. It turned on to teh menu, I moved to shuffle and selected that. SOngs are playing. But now no

  • GUI Update

    I am a newbie in using Swing. I was written a GUI class and a application. When i run the Gui and click a button on it to start the application program, the gui has no response, only the application is running. I think i should use thread, but i real

  • Bluetooth Peripheral Device driver failure in Windows Vista

    I've linked my computer and my Palm Centro using a Bluetooth connection and now I keep getting an error message that says... "Device driver was not successfully installed...Bluetooth Peripheral Device - Failed" It tries to search the computer to find

  • Why does VISA write vi get a clock symbol added?

    In an application, I was using the older serial I/O primitive vi's, and now that I've switched to LV 7.1, I wanted to change the older serial read and write (worked fine) vi's (not VISAs) to the VISA Read and Write. When I place a VISA write on the b