Email delivery to non-existent addresses

Stephan M. Greve 96 Reputation points
2020-11-12T19:50:02.953+00:00

We use a Cloud service for security scanning with our mailflow, we are using a smtp-call-ahead with it to identify existing addresses in Exchange online, this stopped working some weeks ago, because Exchange Online is handling those delivery attempts to non-existent addresses differently. The mails are often accepted for delivery and Exchange online creates the NDR, sometimes we can still see the old behaviour with a rejected delivery, I was able to reproduce the issue with telnet, I'm hoping to gather some information about when Exchange Online answers with 2.1.5 and when with 5.4.1 for addresses not existing...

telnet 104.47.9.36 25

Trying 104.47.9.36...
Connected to mail-ve1eur030036.inbound.protection.outlook.com.
Escape character is '^]'.
220 VE1EUR03FT006.mail.protection.outlook.com Microsoft ESMTP MAIL Service ready at Tue, 10 Nov 2020 21:24:33 +0000
ehlo -deleted-
250-VE1EUR03FT006.mail.protection.outlook.com Hello -deleted-
250-SIZE 157286400
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-STARTTLS
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250 SMTPUTF8
mail from: -deleted-
250 2.1.0 Sender OK
rcpt to: -deleted-
550 5.4.1 Recipient address rejected: Access denied. AS(201806281) [VE1EUR03FT006.eop-EUR03.prod.protection.outlook.com]
quit
221 2.0.0 Service closing transmission channel
Connection closed by foreign host.
telnet 104.47.10.36 25

Trying 104.47.10.36...
Connected to mail-db5eur030036.inbound.protection.outlook.com.
Escape character is '^]'.
220 DB5EUR03FT054.mail.protection.outlook.com Microsoft ESMTP MAIL Service ready at Tue, 10 Nov 2020 21:25:06 +0000
ehlo -deleted-
250-DB5EUR03FT054.mail.protection.outlook.com Hello -deleted-
250-SIZE 157286400
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-STARTTLS
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250 SMTPUTF8
mail from: -deleted-
250 2.1.0 Sender OK
rcpt to: -deleted-
250 2.1.5 Recipient OK
quit
221 2.0.0 Service closing transmission channel
Connection closed by foreign host.

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,599 questions
0 comments No comments
{count} votes

Accepted answer
  1. Stephan M. Greve 96 Reputation points
    2020-11-12T20:07:46.803+00:00

    Hi,

    the issue is about deliveries to addresses that don't exist only, like saldkjfalsdk@Company portal .com, all domains are authoritative and I would see different results with 2.1.5 or 5.4.1 for delivery attempts to saldkjfalsdk@Company portal .com .

    Thank you for your help!

    stephan


1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 149.5K Reputation points MVP
    2020-11-12T19:55:58.773+00:00

    Alot of that depends if the accepted domain in Exchange Online is set to authoritative or not.
    If set to authoritative, then it will reject the message to an invalid recipient at the gateway:
    550 5.4.1 Recipient address rejected: Access denied. AS(201806281) [

    If not and the accepted domain is set to internal relay, it will accept the message and attempt to route it to another system ( such as hybrid archictecture with an on-prem component) and NDR it later if not found.

    So, I guess the question is are you seeing different results sending to the same user or to the same domain?

    https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/manage-accepted-domains/manage-accepted-domains

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.