Hotmail Senders receiving NDR : "550-Please turn on SMTP Authentication in your mail client..."

11,395

Is your Exchange Server configured to be autoritative for this Domain?

Hub Transport -> Accepted Domains

Share:
11,395

Related videos on Youtube

DKNUCKLES
Author by

DKNUCKLES

Penetration Tester / InfoSec Consultant, OSCP / OSCE, educator to anyone wanting to keep their information safe. Always be learning.

Updated on September 18, 2022

Comments

  • DKNUCKLES
    DKNUCKLES almost 2 years

    Recently, senders from Hotmail have begun to get the following NDR when trying to e-mail our domain.

    EDIT : Full NDR Message

    Action: failed Status: 5.5.0 Diagnostic-Code: smtp;550-Please turn on SMTP Authentication in your mail client, or login to the 550-IMAP/POP3 server before sending your message. 550-snt0-omc3-s36.snt0.hotmail.com [65.55.90.175]:49271 is not permitted to 550 relay through this server without authentication

    This is seemingly out of the blue and I'm at a loss as to why this is happening.

    Pertinent Information

    • We have multiple domains hooked up to our Exchange server. We changed our company name in January of this year, and the old primary domain (olddomain.com) will accept e-mails from Hotmail accounts, however e-mails sent to the new primary domain (newdomain.com) bounce back with the NDR listed above.
    • The bounces only appear to be happening when the Hotmail sender is sending a new e-mail, and not if they are responding to an e-mail sent from our end.
    • We have made no changes to the configuration of our server recently. This e-mail first appeared last Friday.
    • As far as I can tell, the mail doesn't even seem to get to our server
    • We performed an Exchange 2003 to 2010 migration last year. The 2003 acts as a Smart Host

    Any advice on this issue would be greatly appreciated! I'm at a loss

    • Greg Askew
      Greg Askew about 12 years
      When you send an email message from your hotmail account, in the bounced message, what is the ip address and name of the SMTP server that is rejecting your message?
    • DKNUCKLES
      DKNUCKLES about 12 years
      Edited question with full NDR method.
    • MichelZ
      MichelZ about 12 years
      Is it absolutely only hotmail which fails? All others are coming in fine? Really strange...
    • DKNUCKLES
      DKNUCKLES about 12 years
      Hotmail is the only domain I've identified / has been brought to my attention. All other external e-mail works as it should
    • MichelZ
      MichelZ about 12 years
      Just to be sure, can you try testexchangeconnectivity.com If that really works, I think you have to open a case with Microsoft/Hotmail to further troubleshoot
    • DKNUCKLES
      DKNUCKLES about 12 years
      Green lights all around for the inbound SMTP test. I guess Microsoft is my next stop - thank you for your help MichelZ
    • Admin
      Admin about 12 years
      Same situation here, except not using exchange. I am using google accounts for my domain. Any email sent from hotmail/live/msn gets the same ndr. This just started happening and doesn't happen when a client sends from any other mail service
    • DKNUCKLES
      DKNUCKLES about 12 years
      Based on my research it looks as though Google Apps and Exchange servers are the only ones affected by this little 'ism.
    • Admin
      Admin about 12 years
      I also have the same situation. We can send emails to Hotmail, but Hotmail users can not send email to our exchange server. MX, rDNS, SPF are all OK - no issues with any other domains!
    • Admin
      Admin about 12 years
      We have the same problem, started Friday 6/15. Hotmail bounces and gives the same diagnostic code to our google apps mail addresses.
  • DKNUCKLES
    DKNUCKLES about 12 years
    No it is not. The only authoritative domains are the ones that we own.
  • MichelZ
    MichelZ about 12 years
    This is what I mean. your olddomain.com and your newdomain.com are listed here?
  • DKNUCKLES
    DKNUCKLES about 12 years
    Yes both domains are listed there. I apologize for confusion. The odd part here is that olddomain.com is listed as the default, but e-mails are leaving the organization as newdomain.com
  • MichelZ
    MichelZ about 12 years
    The Settings on the individual user decides on what Domain to send as. (the bold SMTP address).
  • DKNUCKLES
    DKNUCKLES about 12 years
    Thank you for your insight on this! I've launched a ticket with Microsoft but have yet to hear back. If /when I do I'll post back.
  • broadway1978
    broadway1978 about 12 years
    As of this morning this problem appears to be resolved. Never got any more insight from MS - but it's working which is the main thing.