Forum Discussion
2019 Hybrid mail flow failure from on prem to exchange online
I've updated things and my mail from EOP to o365 just sits in the EOP mail queue.
[{LED=450 4.7.320 Certificate validation failed [Message=UntrustedRoot] [LastAttemptedServerName=*.mail.onmicrosoft.com]
[LastAttemptedIP=]};{MSG=UntrustedRoot};{FQDN=*.mail.onmicrosoft.com};{IP=*};{LRT=10/19/2023
12:44:59 PM}]
I've installed the 365 bundle on the server, verified my connectors are valid.
Hi Eikehans,
thanks for your update.
The issue still revolves around a certificate validation failure with the FQDN *.mail.onmicrosoft.com.
To address this issue, you can follow these steps for further troubleshooting:
Verify Certificate Installation: Make sure the root certificate for Exchange Online (Office 365) is correctly installed on your on-premises Exchange server. Ensure that you have downloaded and installed the most recent root certificates provided by Microsoft and that the root certificate is located in the Trusted Root Certification Authorities store.
Check Certificate Validity: Confirm that the certificate on the Exchange Online server is not expired. If it has expired, you should consider renewing or replacing it.
Review DNS Configuration: Check that your DNS settings are properly configured to resolve the Fully Qualified Domain Name (FQDN) of the Exchange Online server, which is indicated as *.mail.onmicrosoft.com in your error message. Ensure that the FQDN resolves to the correct IP address.
Examine Firewall and Network: Ensure there are no network or firewall issues blocking your on-premises server from establishing a secure connection with Exchange Online.
Update Send Connector: Double-check your send connector configuration to ensure it correctly uses the new certificate and that the FQDN matches the certificate.
Test Connectivity: Utilize the Test-Mailflow cmdlet to assess mail flow between your on-premises server and Exchange Online. This can help identify and address any connectivity issues.
Check Logs and Event Viewer: Inspect the event logs on your on-premises server for additional error information related to the certificate validation failure.
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
(LinkedIn)