Microsoft Teams Voicemail & Exchange Edge = SenderIdAgent; Missing purported responsible address

%3CLINGO-SUB%20id%3D%22lingo-sub-3342172%22%20slang%3D%22en-US%22%3EMicrosoft%20Teams%20Voicemail%20%26amp%3B%20Exchange%20Edge%20%3D%20SenderIdAgent%3B%20Missing%20purported%20responsible%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3342172%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20are%20still%20an%20Exchange%20on-prem%20company.%26nbsp%3BOur%20MXs%20are%20running%20Exchange%20Edge%202019.%26nbsp%3BThere%20is%20no%20hybrid%20in%20place.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EOur%20department%20responsible%20running%20our%20PBX%20systems%20want%20to%20migrate%20our%20legacy%20PBX%20systems%20to%20Teams.%26nbsp%3BDuring%20tests%20we%20ran%20into%20to%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETeams%20to%20Teams%20calls%20going%20to%20voicemail%20are%20getting%20delivered%20to%20the%20inbox%20of%20the%20user.%3C%2FP%3E%3CP%3EVoicemais%20from%20phone%20numbers%20to%20Teams%20are%20getting%20blocked%20by%20Exchange%20Edge%20SenderIdAgent.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E%3CEM%3E2022-05-06T09%3A26%3A48.526Z%2C08DA29C47ADB060A%2C10.10.10.22%3A25%2C104.47.2.56%3A6284%2C104.47.2.56%2C%2Cnoreply_skype_voicemail_1f47ba59-036a-4809-a3ee-ae162cd7a1c1%40company.com%2C%3CSTRONG%3E%2B35212222222222%3C%2FSTRONG%3E%3B%2Cuser%40company.com%2C1%2CSender%20Id%20Agent%2COnEndOfHeaders%2CRejectMessage%2C550%205.7.108%20SenderIdAgent%3B%20%3CSTRONG%3EMissing%20purported%20responsible%20address%2CMissingPRA%2CNo%20valid%20PRA%2C%3C%2FSTRONG%3E%2C1e88da3f-b49e-45de-4ae6-08da2f428bbf%2C%2CIncoming%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FEM%3EAfter%20minimal%20research%20we%20found%20out%20that%20it%20is%20true%20that%20the%20voicemails%20sent%20from%20Teams%20have%20a%20FROM%20address%20which%20is%20not%20formatted%20in%20a%20RFC%20compliant%20manner%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Ftroubleshoot%2Fhybrid-phone-system%2Fvoicemails-not-delivered%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EVoicemail%20messages%20aren't%20delivered%20in%20Teams%20or%20Skype%20for%20Business%20client%20-%20Skype%20for%20Business%20%7C%20Microsoft%20Docs%3C%2FA%3E%3CBR%20%2F%3E%22The%20primary%20issue%20that%20affects%20third-party%20email%20systems%20is%20that%20the%20FROM%20address%20is%20formatted%20for%20PSTN%20calls%20in%20a%20non%E2%80%93RFC-compliant%20manner.%22%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSTRONG%3EMicrosofts%20workaround%20for%20symptom%201%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CEM%3E%22Add%20the%20Cloud%20Service%20IP%20addresses%20listed%20at%20Office%20365%20URLs%20and%20IP%20address%20ranges%20in%20an%20SPF%20record.%22%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FEM%3E%3CSTRONG%3EWe%20did%20that%2C%20but%20Edge%20still%20does%20not%20accept%20the%20messages.%20We%20doublechecked%20the%20record%2C%20it%20is%20valid.%3C%2FSTRONG%3E%3CEM%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FEM%3EMicrosofts%20alternative%20recommendation%20is%3A%3CEM%3E%3CBR%20%2F%3EAlternatively%2C%20create%20a%20transport%20rule%20to%20bypass%20the%20spam%20filtering%20for%20Cloud%20Voicemail%20coming%20from%20them.%22%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20my%20questions%20are%3A%3CBR%20%2F%3E%3C%2FEM%3EWhat%20IP%20addresses%20do%20we%20need%20to%20whitelist%20on%20Edge%3F%3CBR%20%2F%3EIt%20looks%20like%20that%20you%20have%20to%20whitelist%20the%20whole%20O365%20universe%20and%20our%20company%20doesn't%20want%20to%20do%20that.%20What%20if%20another%20account%2Ftenant%20in%20O365%20gets%20compromised%20and%20starts%20sending%20spam%20towards%20our%20org%3F%3CBR%20%2F%3E%3CBR%20%2F%3EWhat's%20the%20best%20way%20to%20solve%20this%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20and%20have%20great%20day!%3CBR%20%2F%3E%3CEM%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3342172%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ETeams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

Hello,

 

we are still an Exchange on-prem company. Our MXs are running Exchange Edge 2019. There is no hybrid in place.


Our department responsible running our PBX systems want to migrate our legacy PBX systems to Teams. During tests we ran into to following:

 

Teams to Teams calls going to voicemail are getting delivered to the inbox of the user.

Voicemais from phone numbers to Teams are getting blocked by Exchange Edge SenderIdAgent.


2022-05-06T09:26:48.526Z,08DA29C47ADB060A,10.10.10.22:25,104.47.2.56:6284,104.47.2.56,,noreply_skype_voicemail_1f47ba59-036a-4809-a3ee-ae162cd7a1c1@company.com,+35212222222222;,user@company.com,1,Sender Id Agent,OnEndOfHeaders,RejectMessage,550 5.7.108 SenderIdAgent; Missing purported responsible address,MissingPRA,No valid PRA,,1e88da3f-b49e-45de-4ae6-08da2f428bbf,,Incoming

After minimal research we found out that it is true that the voicemails sent from Teams have a FROM address which is not formatted in a RFC compliant manner:
Voicemail messages aren't delivered in Teams or Skype for Business client - Skype for Business | Mic...
"The primary issue that affects third-party email systems is that the FROM address is formatted for PSTN calls in a non–RFC-compliant manner."

Microsofts workaround for symptom 1
"Add the Cloud Service IP addresses listed at Office 365 URLs and IP address ranges in an SPF record."

We did that, but Edge still does not accept the messages. We doublechecked the record, it is valid.

Microsofts alternative recommendation is:
Alternatively, create a transport rule to bypass the spam filtering for Cloud Voicemail coming from them."

So my questions are:
What IP addresses do we need to whitelist on Edge?
It looks like that you have to whitelist the whole O365 universe and our company doesn't want to do that. What if another account/tenant in O365 gets compromised and starts sending spam towards our org?

What's the best way to solve this?

Thank you and have great day!




 

 

0 Replies