SOLVED

NDR from Office 365 to On-prem Mailboxes

%3CLINGO-SUB%20id%3D%22lingo-sub-278008%22%20slang%3D%22en-US%22%3ENDR%20from%20Office%20365%20to%20On-prem%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278008%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20in%20the%20process%20of%20moving%20my%20organization%20to%20Office%20365.%26nbsp%3B%20My%20Exchange%20server%20is%202010%20and%20I%20am%20using%20the%20minimal%20hybrid%20option.%26nbsp%3B%20I've%20ran%20the%20HCW%20and%20set%20up%20Azure%20AD%20Connect%20and%20I'm%20in%20the%20process%20of%20testing%20the%20hybrid%20configuration.%26nbsp%3B%20I'm%20finding%20that%20I%20can%20send%20email%20from%20on-prem%20mailboxes%20to%20remote%20mailboxes%20in%20Office%20365%20that%20I%20created%20from%20the%20Exchange%202010%20EMC.%26nbsp%3B%20But%20when%20sending%20from%20a%20remote%20mailbox%20in%20Office%20365%20to%20an%20on-prem%20mailbox%2C%20I%20get%20an%20NDR%20with%20error%3A%26nbsp%3B%3C%2FP%3E%3CTABLE%3E%3CTBODY%3E%3CTR%3E%3CTD%3E%3CFONT%20face%3D%22Segoe%20UI%2CFrutiger%2CArial%2Csans-serif%22%20size%3D%222%22%3E%3CSPAN%3E%3CI%3E550%205.1.351%20Remote%20server%20returned%20unknown%20recipient%20or%20mailbox%20unavailable%20-%26gt%3B%20550%20Requested%20action%20not%20taken%3A%20mailbox%20unavailable%3C%2FI%3E%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FTD%3E%3C%2FTR%3E%3C%2FTBODY%3E%3C%2FTABLE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20found%20this%20KB%20article%20but%20I%20do%20not%20see%20the%20%22Shared%22%20option%20in%20the%20properties%20window%20for%20my%20domain.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2730609%2Fon-premises-users-aren-t-getting-email-messages-from-office-365-users%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2730609%2Fon-premises-users-aren-t-getting-email-messages-from-office-365-users%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EMike%20D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-278008%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278471%22%20slang%3D%22en-US%22%3ERe%3A%20NDR%20from%20Office%20365%20to%20On-prem%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278471%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Mike%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20the%20connector%20is%20configured%20correctly%2C%20it%20should%20forward%20any%20mail%20that%20has%20that%20domain%20to%20your%20on%20prem%20exchange%20server.%20The%20Mail%20user%20objects%20are%20there%20for%20users%20you%20may%20eventually%20migrate%20over.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20that%20said%2C%20I%20would%20say%20this%20is%20a%20problem%20with%20your%20routing.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Set%20the%20domain%20you%20are%20using%20to%20internal%20relay.%20That%20is%20the%20setting%20that%20should%20be%20enabled.%20That%20means%20%22dont%20go%20look%20at%20the%20outside%20world.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20If%20your%20connectors%20are%20setup%2C%20this%20means%20that%20the%20mailbox%20should%20only%20ever%20exist%20on%20prem%20or%20on%20O365.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EIf%20you%20had%20mail%20user%20objects%20for%20all%20your%20users%2C%20or%20when%20you%20are%20done%20migrating%2C%20the%20domain%20should%20be%20authoritative.%20You%20can%20see%20what%20the%20different%20settings%20mean%20here%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fmanage-accepted-domains%2Fmanage-accepted-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fmanage-accepted-domains%2Fmanage-accepted-domains%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20your%20description%2C%20right%20now%20you%20need%20to%20be%20internal%20relay%2C%20and%20ensure%20you%20have%20your%20connector%20setup%20right.%20If%20you%20change%20it%20to%20internal%20relay%2C%20and%20are%20still%20having%20issues%20an%20hour%20from%20now%2C%20re-run%20the%20HCW%20to%20reconfigure%20your%20connector.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278046%22%20slang%3D%22en-US%22%3ERe%3A%20NDR%20from%20Office%20365%20to%20On-prem%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278046%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20the%20reply.%26nbsp%3B%20The%20NDR%20is%20from%20Office%20365.%26nbsp%3B%20When%20I%20look%20at%20Recpients%20%26gt%3B%20Contacts%20in%20the%20Exchange%20Admin%20center%2C%20I%20do%20see%20a%20mail%20user%20object%20for%20the%20on-prem%20mailbox%20that%20I'm%20trying%20to%20send%20to.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-278030%22%20slang%3D%22en-US%22%3ERe%3A%20NDR%20from%20Office%20365%20to%20On-prem%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-278030%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Mike%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20be%20interested%20to%20know%20if%20it%20is%20O365%20or%20your%202010%20server%20doing%20the%20bouncing.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20setup%20the%20HCW%20correctly%2C%20than%20the%20connectors%20put%20in%20place%20should%20handle%20mailflow%20for%20you.%20You%20should%20not%20have%20to%20go%20and%20change%20any%20settings%20with%20your%20domain%2C%20the%20HCW%20should%20put%20in%20place%20everything%20you%20need%20to%20flow%20properly.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20it%20is%20making%20it%20out%20of%20O365%20and%20you%20are%20getting%20that%20error%2C%20it%20could%20be%20something%20like%20firewall%20related.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20it%20is%20not%20making%20it%20out%20of%20O365%2C%20than%20it%20is%20likely%20something%20in%20your%20settings%20or%20exchange%20connector.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20is%20there%20a%20mail%20user%20in%20O365%20for%20the%20address%3F%20Those%20are%20created%20from%20AADC%20when%20an%20account%20exists%20on%20prem%20but%20has%20yet%20to%20be%20migrated.%20It%20creates%20the%20mail%20user%20in%20O365%20so%20you%20know%20it%20exists%20as%20an%20object%2C%20but%20will%20route%20the%20mail%20to%20on-prem.%20It%20would%20be%20worth%20checking%20if%20that%20is%20the%20case.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hello,

 

I'm in the process of moving my organization to Office 365.  My Exchange server is 2010 and I am using the minimal hybrid option.  I've ran the HCW and set up Azure AD Connect and I'm in the process of testing the hybrid configuration.  I'm finding that I can send email from on-prem mailboxes to remote mailboxes in Office 365 that I created from the Exchange 2010 EMC.  But when sending from a remote mailbox in Office 365 to an on-prem mailbox, I get an NDR with error: 

550 5.1.351 Remote server returned unknown recipient or mailbox unavailable -> 550 Requested action not taken: mailbox unavailable

 

I found this KB article but I do not see the "Shared" option in the properties window for my domain.

https://support.microsoft.com/en-us/help/2730609/on-premises-users-aren-t-getting-email-messages-fro...

 

Thanks,

Mike D

 

3 Replies
Highlighted

Hey Mike,

 

I would be interested to know if it is O365 or your 2010 server doing the bouncing.

 

If you setup the HCW correctly, than the connectors put in place should handle mailflow for you. You should not have to go and change any settings with your domain, the HCW should put in place everything you need to flow properly.

 

If it is making it out of O365 and you are getting that error, it could be something like firewall related.

 

If it is not making it out of O365, than it is likely something in your settings or exchange connector.

 

Also is there a mail user in O365 for the address? Those are created from AADC when an account exists on prem but has yet to be migrated. It creates the mail user in O365 so you know it exists as an object, but will route the mail to on-prem. It would be worth checking if that is the case.

 

Adam

 

Highlighted

Hello,

 

Thank you for the reply.  The NDR is from Office 365.  When I look at Recpients > Contacts in the Exchange Admin center, I do see a mail user object for the on-prem mailbox that I'm trying to send to.

Highlighted
Solution

Hey Mike,

 

If the connector is configured correctly, it should forward any mail that has that domain to your on prem exchange server. The Mail user objects are there for users you may eventually migrate over.

 

With that said, I would say this is a problem with your routing.

 

1. Set the domain you are using to internal relay. That is the setting that should be enabled. That means "dont go look at the outside world."

 

2. If your connectors are setup, this means that the mailbox should only ever exist on prem or on O365.


If you had mail user objects for all your users, or when you are done migrating, the domain should be authoritative. You can see what the different settings mean here - https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/manage-accepted-domains/manage-ac...

 

From your description, right now you need to be internal relay, and ensure you have your connector setup right. If you change it to internal relay, and are still having issues an hour from now, re-run the HCW to reconfigure your connector.

 

Adam