question

Chong-7118 avatar image
0 Votes"
Chong-7118 asked KaelYao-MSFT commented

NDR 550 5.7.1 Cross-forest send email to mailbox which forward to distribution group

Hi,

We use ADMT to migrate domain from A to B, and also move some of the ex2016 mailbox in domain A to ex2019 in domain B. Some mailboxes in domain A configured auto forward to a domain A distribution group, the group set to delivery by “only sender inside my organization”

We found when domain B user send to these domain A mailboxes, they will receive a NDR from domain A Exchange said “Remote Server returned '550 5.7.1 RESOLVER.RST.AuthRequired; authentication required“.
Tested if they send to the group directly, the email can send out normally.

How can we solve the NDR problem so domain B user can send email to these mailbox and also forward to group?


Chong

office-exchange-server-administrationoffice-exchange-server-mailflow
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

KaelYao-MSFT avatar image
0 Votes"
KaelYao-MSFT answered KaelYao-MSFT commented

Hi Chong,

Did you mean if Domain B mailboxes send to Domain A mailboxes (which are configured to auto-forward to distribution groups in Domain A), they would receive this NDR message?
If yes, I suppose it is the expected behavior.

The whole process would be like:
1.Domain B mailbox sends to a mailbox in Domain A
2.Due to the delivery option setting on the mailbox in Domain A, the message is redirected to the distribution group during transport
3.The forwarded message is considered sent from outside the organization, and since the group delivery option is "only sender inside my organization", the message gets rejected.

You may also see it via message tracking:
203461-26.png


To solve this issue, you may create mailbox contacts for the mailboxes (which are currently in Domain B) on Exchange in Domain A and configure the distribution group to accept messages from these contacts ,and also the mailboxes used to forward to this group in Domain A.
203511-27.png


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


26.png (16.5 KiB)
27.png (35.3 KiB)
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @KaelYao-MSFT ,

When we enable the "Senders inside and outside of my organization" options, all sender can send to this distribution group.

Then if I add the mail contact and mailbox in the list you show, only them can send to this group. Base on your sample, only "migrate01-migrate02" and "migrate03" (also inside organization) can send to this group, the other email outside of the organization cannot send?

Thanks

Chong

0 Votes 0 ·

Hi,

Yes. If you don't have any specific senders added in the field below, all internal and external senders would also be able to send to this distribution group.
However, it can be limited via adding senders to the field.

Please refer to this link: Delivery management
203528-29.png


In the example, only migrate01-domain2 (mail contact so it is external) and migrate03 (internal) can send to this distribution group.
Other external senders would receive this NDR message:
203611-30.png

For internal senders, besides the NDR message above, they would also see this MailTip when they try to send to this distribution group:

203557-31.png


0 Votes 0 ·
29.png (51.7 KiB)
30.png (11.7 KiB)
31.png (6.9 KiB)