{"id":114,"date":"2009-10-06T10:06:45","date_gmt":"2009-10-06T09:06:45","guid":{"rendered":"https:\/\/harun.se\/blog\/?p=114"},"modified":"2009-12-13T03:00:40","modified_gmt":"2009-12-13T02:00:40","slug":"how-to-allow-the-internal-application-servers-to-relay-smtp-messages-thru-exchange-server-2007","status":"publish","type":"post","link":"https:\/\/harun.se\/blog\/?p=114","title":{"rendered":"How to allow the internal application servers to relay SMTP Messages thru Exchange Server 2010 and 2007"},"content":{"rendered":"<p>if you are getting the SMTP error message &#8220;550 5.7.1 Unable to relay&#8221; when you try to relay smtp messages thru your exchange server, you have to configure a new receive connector by following the steps below<\/p>\n<p>SMTP applications that can authenticate to relay messages does not have this problem so this configuration is <strong>strictly<\/strong> for those applications that cannot authenticate with Exchange 2010..<\/p>\n<p>First step is to create a new custom receive connector to be able to scope remote IP Addresses of the application servers that we will allow.<\/p>\n<p>Start your Exchange Management Console -&gt; Expand the Server Configuration and click on Hub Transport-&gt; Click on the &#8220;New Receive Connector&#8221;<\/p>\n<p>\u00a0<\/p>\n<p>Enter an approtiate name and\u00a0 Click NEXT<\/p>\n<p>In the &#8220;Remote Network settings&#8221; window, remove the existing range that is already suggested in the window,<\/p>\n<p>Click &#8220;Add&#8221; to enter the IP Adresses\/ranges of the application servers that will be allowed to relay SMTP messages, Click OK and Next<br \/>\nClick New and Finish<\/p>\n<p>Check\u00a0Properties\u00a0of the new connector\u00a0<\/p>\n<p>Click on the Authentication Tab, clear all the check boxes and choose the Exchange server authentication check box\u00a0<\/p>\n<p>Click on the Permissions Group Tab and check the Anonymous users box\u00a0<\/p>\n<p>The next step is to create the connector, and open the properties. Now you have two options, which I will present. The first option will probably be the most common.<\/p>\n<p><strong><em>Option 1: Make your new scoped connector an Externally Secured connector<\/em><\/strong><\/p>\n<p>This option is the most common option, and preferred in most situations where the application that is submitting will be submitting email to your internal users as well as relaying to the outside world.<\/p>\n<p>Before you can perform this step, it is required that you enable the Exchange Servers permission group. Once in the properties, go to the Permissions Groups tab and select Exchange servers.<\/p>\n<p><a href=\"http:\/\/msexchangeteam.com\/photos\/postpictures2\/images\/432010\/original.aspx\"><\/a><\/p>\n<p>Next, continue to the authentication mechanisms page and add the &#8220;Externally secured&#8221; mechanism. What this means is that you have complete trust that the previously designated IP addresses will be trusted by your organization.<\/p>\n<p><a href=\"http:\/\/msexchangeteam.com\/photos\/postpictures2\/images\/432011\/original.aspx\"><\/a><\/p>\n<p><strong>How to Grant the relay permission to Anonymous users on the new connector?<\/strong><\/p>\n<p>Check the &#8220;Anonymous users&#8221; box<\/p>\n<p><a href=\"http:\/\/msexchangeteam.com\/photos\/postpictures2\/images\/432012\/original.aspx\"><\/a><\/p>\n<p>This will grant permissions for the anonymous account, but not the permission to relay. This should be done thru the Exchange shell:<\/p>\n<p>Get-ReceiveConnector &#8220;Haruns Application Relay&#8221; | Add-ADPermission -User &#8220;NT AUTHORITY\\ANONYMOUS LOGON&#8221; -ExtendedRights &#8220;ms-Exch-SMTP-Accept-Any-Recipient&#8221;<\/p>\n<p>That&#8217;s it \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>if you are getting the SMTP error message &#8220;550 5.7.1 Unable to relay&#8221; when you try to relay smtp messages thru your exchange server, you have to configure a new receive connector by following the steps below SMTP applications that can authenticate to relay messages does not have this problem so this configuration is strictly [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[10,8],"tags":[],"_links":{"self":[{"href":"https:\/\/harun.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/114"}],"collection":[{"href":"https:\/\/harun.se\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/harun.se\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/harun.se\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/harun.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=114"}],"version-history":[{"count":8,"href":"https:\/\/harun.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/114\/revisions"}],"predecessor-version":[{"id":119,"href":"https:\/\/harun.se\/blog\/index.php?rest_route=\/wp\/v2\/posts\/114\/revisions\/119"}],"wp:attachment":[{"href":"https:\/\/harun.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/harun.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/harun.se\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}