Exchange 2016 accepted domain type:internal relay

Pero 66 Reputation points
2021-01-14T14:26:51.82+00:00

Hello all,

In exchange 2016 we have setup "accepted domains". But later we created Accepted domain with "*" under domain type this one is "Internal relay".

As far as I know having "accepted domain" with "*" makes exchange an "open relay" what is everything we don't want.

Does "accepted domain" with "*" Domain type "internal relay" makes exchange an open relay ?

Thank you,
Pero

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,489 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,606 questions
0 comments No comments
{count} votes

Accepted answer
  1. Eric Yin-MSFT 4,386 Reputation points
    2021-01-15T07:47:54.61+00:00

    If you have created a connector accepts all IPs on port 25 with "ms-Exch-SMTP-Accept-Any-Recipient" permission, then it becomes open relay.
    You should get the following warning when you set internal relay for "*" , why you still insist on it?
    57008-3.png


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 147.7K Reputation points MVP
    2021-01-14T14:31:26.597+00:00

    What it tells Exchange is that if the recipient can't be found, then send the message to another shared mail system that matches.

    HOWEVER, you should not have an accepted domain with a wildcard unless its set for a subdomain like *.contoso.com
    You should only have accepted domains that represent the actual SMTP domains you accept for and if you are authoritative, then they should be set that way

    Why was one created for * ?

    https://learn.microsoft.com/en-us/exchange/mail-flow/accepted-domains/accepted-domains?view=exchserver-2019

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.