Exchange server still acts authoritative for removed accepted domain
Hi all, I am using exchange 2007.. we had 4 domains but one has moved to another company.. I am trying to remove this domain from our exchange server. I did the following. 1. In exchange management console I removed the domain in question from accepted domains 2. In exchange management console I removed email address policy for the old domain 3. Removed the old email address from any email accounts 4. Restarted exchange 5. MX record was changed and resolves correctly to the new company IP Address I ran command "Get-AcceptedDomain" from the command shell in exchange and correctly got just the 3 Existing Domains returned. I also checked metabase.xml and there is no reference to old domain However, When I send a test email from within our company it goes to the local mailbox of the old email address instead of going externally to the new company? If I remove the users completely and send a test email , I get a bounce back straight away saying user doesn't exist? If I send test email from external email eg Gmail.. Then the email does go correctly to the new company.. If I send test email from outlook web access everything is ok !! If I send test email to an account that vere existed test@olddoamin.com then the email does try sending externaly !! Exchange is still acting like it owns the old domain for previous users..!!! There are numerous people with this issue on the forums but none of their solutions have worked for me.. Please help..
February 14th, 2011 5:59am

If it works from OWA, then the problem is not with Exchange. My instinct is that the OAB hasn't updated correctly, or the clients haven't downloaded an updated version of the OAB. If you look in Outlook at the properties of the user, does the old email address still show? If so, then that is the problem. Exchange doesn't use the SMTP address internally, all it does is use it as a way of looking up the user. If it can match the email address to a user account then the email will go through. Force the OAB to update using get-offlineaddressbook | update-offlineaddressbook Wait about 30 minutes, then download the OAB from the Send/Receive menu in Outlook. Verify the information has changed. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources | In the UK? Hire Me.
Free Windows Admin Tool Kit Click here and download it now
February 14th, 2011 9:41am

Hiya and thx for the reply.. I think you are onto something regarding the OAB. But I think I have a bigger issue. If I try setting out of office assistant in outlook 2007 it fails If I try setting out of office assistant in outlook 2003 it's ok This is back to an issue regarding getting autodiscovery to wotk in 2007. If I hold ctrl on outlook 2007 icon and test autodiscover I get the error autoconfiguration was unable to determine your settings !! I think this is my problem..If autodiscovery doesn't work then OAB won't work etc.. However if I check on exchange server itself with command "test-outlookwebservices" I get "Success The Autodiscover service was tested successfully". Any ideas how to sort the autodiscover problem..? My DNS DOES have an a record for autodisocver.mydomain.com Ray..
February 15th, 2011 6:57am

The autodiscover DNS record isn't used internally unless the clients are not on the domain. The information comes from the domain instead. Outlook 2007 and 2003 get the OOTO information in different ways. The first thing I would do is check the autodiscover URL is correct. In EMS, run get-clientaccessserver |fl Look for autodiscoverinternalURI. The value should resolve internally to your Exchange server, and ideally match the one of the names on your SSL certificate. Also check get-oabvirtualdirectory |fl and verify the URLs are correct. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources | In the UK? Hire Me.
Free Windows Admin Tool Kit Click here and download it now
February 15th, 2011 8:38am

Hiya Simon and thx for your help so far.. Could I email you the results of get-clientaccessserver |fl and get-oabvirtualdirectory |fl I don't want to post them on the forum. Could you send me an email ? rwaldron@sigma.ie please. My problem is that I am picking up the admin of this server from someone else and I don't know what the autodiscovery url should be ... I assume I check in IIS on exchange.. Could I Email you please ? Ray..
February 15th, 2011 9:49am

I don't do direct off site support as that is unfair to my paying clients. If you don't want to post the information on this site, then change the important bits. The only values are those that I have pointed to above, which should resolve to your server, not somewhere else. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources | In the UK? Hire Me.
Free Windows Admin Tool Kit Click here and download it now
February 15th, 2011 11:43am

Ok simon..Here you Go and i do appretiate the help.. Below are the returned values and also command used when creating cert ... What needs to match up? get-clientaccessserver |fl Name : EX07SG01 OutlookAnywhereEnabled : True AutoDiscoverServiceCN : ex07sg01 AutoDiscoverServiceClassName : ms-Exchange-AutoDiscover-Service AutoDiscoverServiceInternalUri : https://ex07sg01.sgdi.sigmaireland.ie/Autodiscover/Autodiscover.xml AutoDiscoverServiceGuid : 77378f46-2c66-4aa9-a6a6-3e7a48b19596 AutoDiscoverSiteScope : {McKee-Ave-Finglas} IsValid : True OriginatingServer : dc07sg02.sgdi.sigmaireland.ie ExchangeVersion : 0.1 (8.0.535.0) DistinguishedName : CN=EX07SG01,CN=Servers,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Sigma Group Organization,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=sgdi,DC=sigmaireland,DC=ie Identity : EX07SG01 Guid : 0085dd8e-8988-4386-93b5-6238deadb4f0 ObjectCategory : sgdi.sigmaireland.ie/Configuration/Schema/ms-Exch-Exchange-Server ObjectClass : {top, server, msExchExchangeServer} WhenChanged : 8/13/2010 12:18:42 PM WhenCreated : 3/5/2008 2:39:55 PM get-oabvirtualdirectory |fl Name : OAB (Default Web Site) PollInterval : 60 OfflineAddressBooks : {Sigma OAB, Default Offline Address Book} RequireSSL : False MetabasePath : IIS://ex07sg01.sgdi.sigmaireland.ie/W3SVC/1/ROOT/OAB Path : C:\Program Files\Microsoft\Exchange Server\ClientAccess\OAB Server : EX07SG01 InternalUrl : https://ex07sg01.sgdi.sigmaireland.ie/OAB InternalAuthenticationMethods : {WindowsIntegrated} ExternalUrl : https://owa.sigma.ie/OAB ExternalAuthenticationMethods : {WindowsIntegrated} AdminDisplayName : ExchangeVersion : 0.1 (8.0.535.0) DistinguishedName : CN=OAB (Default Web Site),CN=HTTP,CN=Protocols,CN=EX07SG01,CN=Servers,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Sigma Group Organization,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=sgdi,DC=sigmaireland,DC=ie Identity : EX07SG01\OAB (Default Web Site) Guid : 4a1ba9d2-a4d1-4420-a4a1-19b4ada1d513 ObjectCategory : sgdi.sigmaireland.ie/Configuration/Schema/ms-Exch-OAB-Virtual-Directory ObjectClass : {top, msExchVirtualDirectory, msExchOABVirtualDirectory} WhenChanged : 11/4/2009 3:35:57 PM WhenCreated : 7/16/2009 1:02:25 PM OriginatingServer : dc07sg02.sgdi.sigmaireland.ie IsValid : True cert command below: do I need to add full address to xml file in here? New-exchangecertificate -DomainName mail.sgdi.sigmaireland.ie,sgdi.sigmaireland.ie,ex07sg01,ex07sg01.sgdi.sigmaireland.ie,owa.sigma.ie, autodiscover.sgdi.sigmaireland.ie -SubjectName "CN=mail.sgdi.sigmaireland.ie,O=Sigmaireland Group,DC=SGDI,DC=ie" -PrivateKeyExportable:$True -GenerateRequest:$True -Path "c:\certrequest2010.req"
February 15th, 2011 11:58am

The key point is whether the names on the directories resolves to the correct place. Ideally in the SSL certificate the address that you are using should be there as well. So, if you are using server.example.local then that is one of the address that should be in the SSL request. When it comes to the common name, decide what name you are going to use and then use that for everything external. That can include the OWA, ActiveSync, Outlook Anywhere address. Also check the value of get-autodiscovervirtualdirectory, particularly the authentication methods: InternalAuthenticationMethods : (Basic, Ntlm, WindowsIntegrated) ExternalAuthenticationMethods : (Basic, Ntlm, WindowsIntegrated) Also check the URLs under that last command, they should be blank. If they are not, then use set-autodiscover to set the value as $null. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources | In the UK? Hire Me.
Free Windows Admin Tool Kit Click here and download it now
February 15th, 2011 12:24pm

Hiya Simon... Gues what.. Email autodiscover test is now working...!! This is something to do with a program called webmarshall. .. when its on the test fails. when its off the test passes. webmarshall is used to block certain sites . So this autodiscover faile doesn't seem to be related to my initial issue. I need to look into this more but sadly this doesn't fix my original problem.!!!!! ie: While autodiscover test passes, if I send email to jbloggs@olddomain.com I still get a mail returned saying user not found... the email should be getting sent externally! When I send from owa everything is ok Doh !! ??
February 15th, 2011 1:06pm

Do an export of your exchange config container and search the txt file to see any refernces of olddomain.com. Also I would just do a restart of the server. ldifde -f c:\exchange.txt -d "CN=Microsoft Exchange,CN=Services,CN=Configuration,dc=yourdomain,DC=com" -p subtreeJames Chong MCITP | EA | EMA; MCSE | M+, S+ Security+, Project+, ITIL msexchangetips.blogspot.com
Free Windows Admin Tool Kit Click here and download it now
February 15th, 2011 1:16pm

Look at how you can put an exclusion in to the product so that it doesn't get in the way. If it works from OWA as you expect, but not from Outlook, then it could still be the OAB. Perhaps the product is blocking the OAB download because of the dependency on web services to do that download. You have two options here for testing. 1. Disable that product, then delete any *.OAB files on the workstation. Restart Outlook. A new copy of the OAB will be downloaded. 2. Test it from an installation of Outlook that is NOT in cached mode, which uses live information from the GAL. Simon.Simon Butler, Exchange MVP Blog | Exchange Resources | In the UK? Hire Me.
February 15th, 2011 3:02pm

Hi Jamestechman, Per your description, in my opinion, the issue seems caused by the cach for the outlook, that is NK2 file, it is better to make a test to create a new profile. Some information for you: http://support.microsoft.com/kb/287623 Regards! GavinPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
February 16th, 2011 1:57am

Hi Jamestechman, Per your description, in my opinion, the issue seems caused by the cache for the outlook, that is NK2 file, it is better to make a test to create a new profile. Some information for you: http://support.microsoft.com/kb/287623 Regards! Gavin Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
February 16th, 2011 9:50am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics