ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Enabling RequireTLS on Exchange Send Connectors

    IT Discussion
    tls exchange exchange 2010 starttls email
    7
    59
    11.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by Dashrender

      We talked about this on ML back in the summer here

      https://mangolassi.it/search?term=TLS&in=titlesposts&timeRange=7776000&timeFilter=older&showAs=posts

      Considering the new discussion, https://mangolassi.it/topic/11669/how-to-require-tls-for-outbound-smtp-connections-with-mdaemon/78, I've come back to this and managed to solve the issue I was having.

      From the Exchange management shell run

      Set-SendConnector -Identity <name of send connector> -RequireTLS:$true
      

      Like Linux, if it works you get no response, just a new prompt.

      Time to test send some emails.

      I sent to my O365 account with no issues, to gmail, again no issues. Tried sending one to my Cox.net account - nothing. Looked in the Mail Queue in Exchange - there sits my message with an error

      451 4.4.0 Primary target IP address responded with: "451 5.7.3 Must issue a STARTTLS command first." attempted failover to alternate host, but that did not succeed.  Either there is no alternate host, or delivery failed to all alternate hosts.
      

      I brought up powershell and telneted to gmail's and Cox's email servers and got the following.

      https://i.imgur.com/QeZZ7jb.png

      As we can see, Cox is not offering TLS connections for email receipt.

      I guess I get to make a phone call in the morning.

      1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller
        last edited by

        Probably best to not have business emails going to Cox home freebie accounts.

        1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender
          last edited by

          Does anyone have a yahoo.com email account I can test?

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @Dashrender
            last edited by

            @Dashrender check telegram

            1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender
              last edited by

              While there appears to be a delay at times it is working.

              Here's yahoo's ehlo reply

              https://i.imgur.com/XI7wxKz.png

              1 Reply Last reply Reply Quote 1
              • DashrenderD
                Dashrender
                last edited by

                And hotmail.com

                https://i.imgur.com/1MLSTcf.png

                1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                  DashrenderD 1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @scottalanmiller
                    last edited by

                    @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                    Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                    What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                    scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                      @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                      Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                      What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                      That is odd for sure.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Dashrender
                        last edited by

                        @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                        @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                        Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                        What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                        No wait, that's not odd. SMTP doesn't pass credentials, IMAP does. They are protecting the log in.

                        DashrenderD 1 Reply Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender @scottalanmiller
                          last edited by

                          @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                          @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                          @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                          Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                          What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                          No wait, that's not odd. SMTP doesn't pass credentials, IMAP does. They are protecting the log in.

                          They require logon for sending too.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Dashrender
                            last edited by

                            @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                            @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                            @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                            @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                            Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                            What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                            No wait, that's not odd. SMTP doesn't pass credentials, IMAP does. They are protecting the log in.

                            They require logon for sending too.

                            Wrong part of the connection, though. The SMTP to the other serves doesn't have the creds even if you enter them earlier.

                            DashrenderD 1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                              @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                              @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                              @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                              @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                              Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                              What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                              No wait, that's not odd. SMTP doesn't pass credentials, IMAP does. They are protecting the log in.

                              They require logon for sending too.

                              Wrong part of the connection, though. The SMTP to the other serves doesn't have the creds even if you enter them earlier.

                              I might not understand how email from a client device (like Outlook, Thunderbird) works with regards to SMTP, not MAPI/ActiveSync.

                              My understanding is that authentication is required to keep spammers from relaying through them.

                              brianlittlejohnB 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender
                                last edited by

                                Good news, 5 days so far, and only Cox.net has failed.

                                1 Reply Last reply Reply Quote 1
                                • brianlittlejohnB
                                  brianlittlejohn @Dashrender
                                  last edited by

                                  @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                  @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                                  @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                  @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                                  @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                  @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                                  Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                                  What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                                  No wait, that's not odd. SMTP doesn't pass credentials, IMAP does. They are protecting the log in.

                                  They require logon for sending too.

                                  Wrong part of the connection, though. The SMTP to the other serves doesn't have the creds even if you enter them earlier.

                                  I might not understand how email from a client device (like Outlook, Thunderbird) works with regards to SMTP, not MAPI/ActiveSync.

                                  My understanding is that authentication is required to keep spammers from relaying through them.

                                  They require credentials to relay outgoing messages to external domains, but incoming messages for cox.net the smtp server accepts without authentication.

                                  DashrenderD 1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender
                                    last edited by

                                    spoke to soon, just people aren't reporting issues.

                                    https://i.imgur.com/Z0O4DcO.png

                                    This is a lawfirm. 😞

                                    JaredBuschJ 2 Replies Last reply Reply Quote 2
                                    • DashrenderD
                                      Dashrender @brianlittlejohn
                                      last edited by

                                      @brianlittlejohn said in Enabling RequireTLS on Exchange Send Connectors:

                                      @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                      @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                                      @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                      @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                                      @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                      @scottalanmiller said in Enabling RequireTLS on Exchange Send Connectors:

                                      Looks like only some silly home user freebie email addresses likely to be an issue. Those people all have the option of good, free secure email if they need access like that, too.

                                      What's weird is that Cox requires the use of TLS to download your email through pop or IMAP.

                                      No wait, that's not odd. SMTP doesn't pass credentials, IMAP does. They are protecting the log in.

                                      They require logon for sending too.

                                      Wrong part of the connection, though. The SMTP to the other serves doesn't have the creds even if you enter them earlier.

                                      I might not understand how email from a client device (like Outlook, Thunderbird) works with regards to SMTP, not MAPI/ActiveSync.

                                      My understanding is that authentication is required to keep spammers from relaying through them.

                                      They require credentials to relay outgoing messages to external domains, but incoming messages for cox.net the smtp server accepts without authentication.

                                      Right - I understand this for normal server to server SMTP, but I'm talking about client to server SMTP.
                                      could they be, sure, and if they are, well then SMTP doesn't need to be authenticated unless the sending side is trying to have Cox act as a relay.

                                      1 Reply Last reply Reply Quote 0
                                      • JaredBuschJ
                                        JaredBusch @Dashrender
                                        last edited by JaredBusch

                                        @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                        spoke to soon, just people aren't reporting issues.

                                        But are people handling it with the recipient another way? If so, win.

                                        DashrenderD 1 Reply Last reply Reply Quote 0
                                        • JaredBuschJ
                                          JaredBusch @Dashrender
                                          last edited by

                                          @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                          https://i.imgur.com/Z0O4DcO.png

                                          This is a lawfirm. 😞

                                          With a local server not behind some spam service I bet.

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @JaredBusch
                                            last edited by

                                            @JaredBusch said in Enabling RequireTLS on Exchange Send Connectors:

                                            @Dashrender said in Enabling RequireTLS on Exchange Send Connectors:

                                            spoke to soon, just people aren't reporting issues.

                                            But are people handling it with the recipient another way? If so, win.

                                            Well the boss just called and said - I have a problem - fix it. Sooooo, no they aren't handling it another way, at least not yet.

                                            I've sent a message to their whois listed technical contact.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post