Message wasn't delivered because of security policies
Hello there, We have two mail servers. An old remote mail server hosting ourcompany.net (with active directory for ourcompany.net) and a new Exchange 2007 server that we just set up for ourcompany.com (also active directory for ourcompany.com). Our domains are completely separate. The new .com setup is running on two physical servers. Server 1 is our mail server with everything except the Edge Transport. Server 2 is our DMZ Edge Transport server. Both our .com and our .net emails work fine. We can send mail to outside addresses with no problems. However, when we use OWA or Outlook on the new setup we cannot send mail to our old server located at ourcompany.net. They can send email to us but we can't send mail to them. The error that we get is: --- Your message wasn't delivered because of security policies. Microsoft Exchange will not try to redeliver this message for you. Please provide the following diagnostic text to your system administrator. The following organization rejected your message: mail.ourcompany.com. mail.ourcompany.com #530 5.7.1 Client was not authenticated ## --- Client not authenticated would make sense if we could not send mail to any external addresses but why would one address work and another not? Clients must be getting authenticated if we can send email everywhere else? We don't allow for anonymous access or relay. Thank you for the help, Chris
February 17th, 2011 7:19pm

Hi, Are you able to send mails to the old server from an Outlook client on the new system? Normally the "530 5.7.1 Client was not authenticated" is a problem with the receive connector not allowing anonymous mails comming in, and since most mails will be anonymous a lot will get this error. Your edge transport should allow anonymous e-mails comming in, otherwise you will only get mails from your internal users. /MartinExchange is a passion not just a collaboration software.
Free Windows Admin Tool Kit Click here and download it now
February 17th, 2011 7:28pm

Hi Martin, That's the thing, I can't send any emails from the new server to the old. But I can send emails from the old to the new. The new server receives emails from any domain and can send to any domain as well. The only problem we've found so far is not being able to send from the new .com server to the old .net server. The other way is fine. EdgeSync seems to have set everything up properly. The Edge recieve connector allows for annonymous mail. However, if I set the Default receive connector on the mail server (not edge but the server with Hub Transport and CAS) to Anonymous, the error I then get is: mail.ourcompany.com #550 5.7.1 Unable to relay ## It seems like whenever we try to email the old .net server we somehow don't get authenticated. Can this have something to do with the domains being similar? Maybe something with ADAM? Thank again, Chris
February 17th, 2011 7:50pm

Hi Chris Sorry for missing the Outlook part. It seems that your new environment is also listening for E-mail addresses on the old domain. Is the .net addresses also in the new environment? When you have an edge server you should not enable anonymous on the internal hub transport server. Have you tried using the message tracking to see how far the mail goes? /Martin Exchange is a passion not just a collaboration software.
Free Windows Admin Tool Kit Click here and download it now
February 17th, 2011 7:59pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics