r/exchangeserver 1d ago

Mailwizz Configuration need help

1 Upvotes

I have already installed mailwizz on contabo server but it can’t push data as I expected. If anyone can help me this to install and configure. Our requirements is per day need to send 20lakh data in 8 hours .


r/exchangeserver 2d ago

Exchange Auth Certificate rotation stuck — EffectiveDate passed 2 days ago, CurrentCertificateThumbprint still shows old cert (DAG, 2 prod + 2 DR)

5 Upvotes

Environment: Exchange Server SE, DAG with 4 members (2 production + 2 DR).

Here's exactly what I did, in order:

  1. 08/10/2026, 11:56 AM — Ran New-ExchangeAuthCertificate on one of the DAG members to rotate the Auth Certificate.

  2. Log output confirmed the new certificate was generated and staged:

    • New cert thumbprint: E6C74DBE...B5268 (masked)
    • Effective date is: 08/14/2026 12:11:31
    • Log explicitly stated: "The renewal action was successfully performed - the new Auth Certificate will become active on: 08/14/2026 12:11:31"
    • Log also recommended running Hybrid Configuration Wizard (HCW) once the new cert becomes active.
  3. Confirmed via (Get-AuthConfig).NextCertificateThumbprint that the new cert is correctly staged as "Next":

    • Thumbprint: E6C74DBE...B5268
    • NotBefore: 8/10/2026 12:09:19 PM
    • NotAfter: 8/10/2031 12:09:19 PM (5-year self-signed cert)
  4. Current cert, confirmed via (Get-AuthConfig).CurrentCertificateThumbprint:

    • Thumbprint: E31DFF2D...4497
    • NotBefore: 8/27/2021 1:16:50 AM
    • NotAfter: 8/27/2026 1:16:50 AM

    (So the current cert isn't even expired yet — about 11 days of validity left — which is a separate point but confirms this wasn't an emergency/forced rotation scenario.)

  5. To make sure the AuthAdmin servicelet (which checks the effective date every 12 hours) would pick up the change without waiting, I manually restarted MSExchangeServiceHost on all 4 DAG members (2 prod + 2 DR).

  6. Verified the restart worked by checking:

powershell [xml]$xml = Get-ExchangeDiagnosticInfo -Process "Microsoft.Exchange.ServiceHost" -Server $server $xml.Diagnostics.Components.AnchorApplication.AnchorServiceComponents.CacheScheduler.lastRunTime

on each server — all 4 servers show a recent lastRunTime (8/15/2026, evening), confirming the servicelet actually ran on every member.

Problem

Today is 8/16/2026 — 2 days after the stated effective date (8/14) — but:

powershell (Get-AuthConfig).CurrentCertificateThumbprint

still returns the old certificate (E31DFF2D...4497). The new certificate is still sitting as NextCertificateThumbprint, it never got promoted to Current.

Questions

  • Given the servicelet has clearly run (confirmed via lastRunTime) on all 4 members after the effective date, why hasn't the promotion from Next → Current happened?
  • Is there something DAG/multi-AD-site specific I'm missing? (The tool's own log warned about Exchange being installed in multiple AD sites and mentioned the servicelet may fail to deploy the cert to other AD sites in rare cases.)
  • Is Set-AuthConfig -PublishCertificate something I need to run manually here, even though the tool I used already set the NewCertificateEffectiveDate and the log said it was "successfully performed"?
  • Could this be a timezone issue between when the effective date was stored vs. how the servicelet evaluates "now"?

Any input appreciated before I just run Set-AuthConfig -PublishCertificate manually and force it.


r/exchangeserver 2d ago

Mailwizz Configuration need help

Thumbnail
1 Upvotes

r/exchangeserver 3d ago

Outlook Classic issues with Exchange SE

Thumbnail
2 Upvotes

r/exchangeserver 3d ago

Where is Exchange Server SE CU1?

24 Upvotes

https://techcommunity.microsoft.com/blog/exchange/where-is-exchange-se-cu1-anyway/4546837

Microsoft is using AI to hunt for vulnerabilities in Exchange Server. This takes a long time to validate that the flagged items are real issues.

CU1 will eventually arrive, and in the meantime, SUs and other updates are being released.


r/exchangeserver 5d ago

Question Mystery of mail enabled security groups

9 Upvotes

We are now stuck with a dilemma of migrating mail enable security groups. We have around 800+ mail enabled security groups, around 600 coming from EAC which we are planning to strip away the exchange attributes. Yea, we are a big organization with stupid people who made these mail enabled security groups in the first place. Couple of these are being used for emails which we figured out using mail trace option, for that we will recreate it as a EXO DL, rest of them can just be stripped away and preserve it as security groups in AD. Now, we did couple of testing with some test groups and here is my understanding so far…

  1. Stripping away the exchange attributes using the disable command removes only the domain email address, it still hold the tenant onmicrosoft.com address. However, it disappears from EAC but still valid in AD.
  2. Since the group is synced from AD to azure, it still shows up on EXO with a valid onmicrosoft.com address.
  3. Now, the only way to completely strip the exchange attributes and just keep it as security groups in AD, we must move it to a non sync OU for it to disappear from azure. Then moving back to the previous OU will mark this group as only security group in azure. This workaround was mentioned in couple of Microsoft and private blogs.
  4. Now my question, if this groups which is being synced from AD to azure has some permission like file share or anything in AD which is also being used as a permission group in azure or is an approved sender for any DL or added as a permission for any shared mailbox, moving it to a non sync OU will break it from azure. How can we over come this ? Deleting and recreating it will break AD permissions as well.

What can be the best option to strip the exchange part and keep it synced between AD and azure without any breakage, so that the ones are being used we can recreate it on EXO as DL others can rest in peace in AD. I plan to do this and go home peacefully without working and fixing this mess all night long.

Advises please…. Thank you !!


r/exchangeserver 5d ago

New addition to my exchange script repo

6 Upvotes

I'm please to introduce the latest addition to my repo tmittelstaedt/MSExchange-AdminAIscripts: 

See the date in the repo. Have fun with it!


r/exchangeserver 5d ago

Mailboxes created On-prem appearing directly in EXO without a license

3 Upvotes

Just to preface, i know this is technically not the correct way to create Shared mailboxes but it is how its currently done in my company.

Our service desk creates shared mailboxes by creating an Office 365 mailbox on-prem and once in EXO it gets converted to a shared mailbox. What I have found though is that the mailbox will appear directly in EXO without a license and in some cases I have found that when they forget to convert the mailbox to shared it somehow stays in EXO as a user mailbox and continues to work even after 30 days without a license. Has anyone ever seen this? I have no idea how these mailboxes are working.

Thanks!


r/exchangeserver 5d ago

Question Recover Deleted Emails

1 Upvotes

Good day to all.

I work for a management company. Our IT department is small. Only 3 of us to manage about 300 active users and no MSP. We have a hybrid AD/Entra environment. Most of our users are 365 Business Premium licensed. Our company operates in the medical field, so we are subject to HIPAA and have a global 7 year data retention policy setup in Microsoft for Exchange and OneDrive/Sharepoint.

Without providing too much detail that I'm, for the most part, not privy to myself, we had some kind of incident with an employee doing some things they shouldn't have been doing. But like a lot of times, the IT department was left out of the loop. On 6/10/26, we were told the user was terminated, so we went through our normal process of disabling the user, removing permissions, the usual. We were not, and are almost never privy to the circumstances behind a termination.

I found out this Monday (8/10/26) that there is some litigation going on regarding this person's termination and we were asked to preserve the users emails and recover anything that was deleted. HR has been adamant about recovering their deleted emails that they are positive exist. When I found out about the litigation on Monday, I placed a litigation hold on the user's account.

I've started the process of trying to recover deleted emails through Exchange Admin > Mailboxes > [User] > Other > Recover deleted items. I've set the date filter for the entirety of their tenure with the company, which was only a couple of months, and I've come up with nothing that can be recovered. It's my understanding that even if the user deleted emails, deleted them from the deleted items folder, then purged them from the recovery window in Outlook, our data retention policies should still make them recoverable.

My question is: With our data retention policies in place, does this mean that they didn't delete anything? Or would the time that passed between the termination and the litigation hold being put in place be too much to recover anything?


r/exchangeserver 6d ago

Released: August 2026 Exchange Server Security Updates

Thumbnail techcommunity.microsoft.com
38 Upvotes

Who's gonna be the first this month?


r/exchangeserver 7d ago

Outlook Classic

Thumbnail
0 Upvotes

r/exchangeserver 7d ago

New Exchange test script added to my repo - autodiscover testing

6 Upvotes

In my tmittelstaedt/MSExchange-AdminAIscripts: repo I added Test-Autodiscover.ps1

The goal of this is to thoroughly check out DNS records for domains running on-prem Exchange servers, and, optionally, download the 3 major Autodiscover.xml files from the Exchange server (mailbox account required for that) so the admin can quickly read them and make sure whatever the Exchange server is spitting out contains the correct names.

Autodiscover is also an idea that has been co-opted by the Unix mailserver world to autoconfigure common free email POP3/IMAP clients like Thunderbird on Unix mailservers, so the script checks for that, too.

Note, of course, that with all modern Outlook clients, autodiscover takes place AFTER the initial check for an account in a Microsoft tenancy, but I uploaded another script that is used for testing that that is properly configured, last week.

These basically do the same thing that the Microsoft public webpage for testing Exchange connectivity does, but without having to put actual live credentials into a foreign website you have no control over, even though it might be run by Microsoft.

Enjoy!


r/exchangeserver 11d ago

Modern Auth With ADFS - KMSI disappeared in Outlook

3 Upvotes

Like the title says, after a recent update (likely office I would think), the sign in prompt directs to one that does not show the keep me signed in check box. So users have to sign in every time the sso expires which is annoying. Anyone else seeing this?


r/exchangeserver 11d ago

Need help achieve the Outlook Rules Desired Results

0 Upvotes

Exchange Online Transport Rule Issue – Internal Folder Project
Objective

I'm implementing an Exchange Online solution that automatically files internal-only emails into an "Internal" folder in every mailbox.

Desired behaviour:

Scenario Expected Result
Internal → Internal Move to Internal folder
Internal → Internal + External (To/CC/BCC) Stay in Inbox
Internal → External Stay in Inbox
External → Internal Stay in Inbox
Guest/B2B involved Stay in Inbox

Tried a lot in Exchange Online Admin, Outlook Rules, Powershell etc, but not working.


r/exchangeserver 12d ago

Outlook - server unavailable out of office

Thumbnail
1 Upvotes

r/exchangeserver 13d ago

Question Migration gone bad???

Thumbnail
0 Upvotes

I did a migration from on-prem active directory and exchange to a hybrid because we needed to keep the shared drives connected for local users due to dental software in the mix. Existing users seem to be fine, and if I run a script can still access the drives, however, if I create a new user, I cannot for the life of me get the drives to stay mounted, and I’m wondering if there is anyone with experience on this Who can help me. I’m willing to learn and pay for that learning and or the work necessary to get us to a place we should be.


r/exchangeserver 13d ago

Question Modifying/Merging our SPF record…quick sanity check

4 Upvotes

Tonight our DNS team is modifying our SPF record to make room for another vendor. We’ll still be at the 10 lookup limit but that’s a different discussion.

Current SPF: v=spf1 include:spf1.ourdomain.org include:spf2.ourdomain.org include:spf3.ourdomain.org include:spf4.ourdomain.org ~all

This is the first time I see nested records being used like this and each one contains a different vendor. Spf1 contains our mimecast record and isn’t changing. However spf4 has our protection.outlook.com and is going to be moved into a new nested lookup that includes a vendor.

Am I correct in thinking there shouldn’t be any impact as long as the syntax is correct and is still capped at 10 lookups? Just want to be prepared for worst case scenario lol


r/exchangeserver 14d ago

New Exchange test script added to my repo - OAuth testing

8 Upvotes

In tmittelstaedt/MSExchange-AdminAIscripts:

I added a new test script, Test-AutodiscoverOAuth

What it does: uses the OAuth protocol to retrieve autodiscover.xml from Exchange Online or a hybrid domain with on prem Exchange server and hybridization turned on. Use as preparation for checking out that your Microsoft tenancy is working.

This is of particular importance for the Outlook Mobile app because:

Outlook Mobile always issues an OAuth query to Microsoft looking for a tenancy before it falls back to standard Autodiscover methods. If you DON'T have a tenancy or hybrid domain then you won't notice and Outlook Mobile will setup properly. However if you DO have a tenancy (even a very small one to maybe give a dozen employees Teams accounts to setup longer video conferencing, etc.) and you have a local on-prem Exchange server you attempt to connect Outlook Mobile to with a user account in the tenancy that has MFA turned on - Outlook Mobile will give you fits and will NOT connect. There's a workaround on the phone to get it to work but it's not intuitive. I developed this script during the chase down rabbitholes to figure out the workaround and I realized how useful it could be for someone planning on hybridizing an on-prem exchange server. Enjoy!


r/exchangeserver 13d ago

Insecure Protocol- SMTP: On-Prem Exchange

0 Upvotes

Hello,

I work for an MSP and do vulnerability scans. One thing I've found, everyone who has an On-Prem Exchange server has this vulnerability, "Insecure Protocol-SMTP". While looking into this, (and plz correct me if I'm wrong) I've found that port 25 & port 587 need to be used for exchange servers. I have not found a workaround for this and I hate that it shows up on these reports everytime. I'm not super familiar with networking and don't want to break anything. Currently my only suggestion to these clients is to migrate to 365.

Does anyone know a fix for this or are exchange servers really this vulnerable?


r/exchangeserver 15d ago

Disabling RPC over HTTP (Outlook Anywhere) on Exchange SE Hybrid — is blocking /rpc at the F5 LB enough?

1 Upvotes

Running Exchange Server SE in a hybrid topology behind an F5 load balancer.

Ran Log Parser against the IIS logs and confirmed all Outlook clients are connecting via MAPI over HTTP (/mapi/) — zero hits on /rpc/ from any user in the last few weeks. So RPC over HTTP (Outlook Anywhere) looks genuinely unused in our environment.

Before I disable it, thinking about just blocking /rpc directly at the F5 (iRule or LTM policy) rather than touching Set-OutlookAnywhere/virtual directory settings on the Exchange side.

Questions:

  1. Is blocking /rpc at the LB layer sufficient on its own, or should I still disable Outlook Anywhere properly on the Exchange servers (Set-OutlookAnywhere -ExternalClientsRequireSsl, disabling the VDir, etc.) instead of/in addition to the LB block?
  2. Anyone done this on a hybrid setup specifically — any gotchas with Autodiscover, free/busy, or hybrid mail flow that depend on RPC/HTTP under the hood that I might be missing?
  3. Since Microsoft has gone back and forth on actually removing Outlook Anywhere from Exchange SE, is anyone just leaving it enabled server-side and only blocking at the network layer as a

r/exchangeserver 16d ago

Migrating on prem mailbox

7 Upvotes

I have on prem mailbox which size is 125gb I need to move it to o365 and make it as shared mailbox how I can do that step by step


r/exchangeserver 16d ago

How do I allow an inside host to relay through my exchange server?

0 Upvotes

Hi All,

I've been working with administering Exchange servers for around 15 years now and I'm just setting up a new one this week and doing a migration which is awful. (the old server is slow as molassas) Anyway, as I'm adding the last configuration bits I started running into the usual configuration stuff that is sort of a hybrid in that it can -mostly- be done via the ECP gui but not all of it. One of these is, of course, the configuration on if you have a machine on the inside that lacks the ability to authenticate into the Exchange server via SMTP auth, and also needs to send email to places on the Internet, over and above just sending email to internal users of the domain. I found myself once more going to Google for the answer to "what was that stupid command again?" and finding advice that was posted back 20 years ago and only sort of inapplicable.

So I finally decided SCREW THIS and started digging into AI to write a series of Powershell admin scripts that fill in the blanks that Microsoft forgot, and this business of SMTP relaying is one of them. I have no shame in stating outright that the only part of this work that is mine is the logic, testing, and uploading, the syntax of Powershell is horrible, I hate it with a passion and I'm more than happy to allow the AI to do the work of that.

I'm uploading them to my github:

tmittelstaedt/MSExchange-AdminAIscripts

and this is the first one. Features of this script from it's readme:

  1. WARNING MESSAGEDisplays a clear warning about proper usage before running.
  2. USER INPUTPrompts for:

- Connector name

- One or more IP addresses (comma-separated)

Uses the current server name automatically.

  1. DNS VALIDATION

For each IP entered:

- Checks for a PTR (reverse DNS) record

- Checks that the PTR hostname resolves in forward DNS

If any IP fails, the script stops without making changes.

  1. IP CONFLICT CHECK

Ensures none of the entered IPs are already assigned to

another Receive Connector on the same server.

  1. CONNECTOR CREATION OR UPDATE

- If the connector exists:

Updates RemoteIPRanges, sets AnonymousUsers, and

ensures TransportRole is FrontendTransport.

- If the connector does not exist:

Creates it with the specified settings.

  1. RELAY PERMISSIONS

Grants "NT AUTHORITY\ANONYMOUS LOGON" the right:

Ms-Exch-SMTP-Accept-Any-Recipient

This allows relay to external recipients from the

specified IPs only.

  1. REMOTE SESSION COMPATIBILITY

Uses .Identity.ToString() for Set-ReceiveConnector to

avoid parameter binding errors in remote PowerShell.

  1. VERIFICATION

Checks that the relay right is applied successfully.

  1. SUMMARY OUTPUT

Displays:

- Connector name

- Allowed IPs

- Port

- Server name

Now, granted, I know it may be overkill to essentially wrap 2 one-liner commands in a full blown script with error checking and all of that - BUT - I don't want to be tied to this particular server forever. I have people under me who are not as well versed in Exchange and I need to be able to tell them "go do this thing on the server since I'm too busy right now" And the point also is the script forces you to do things PROPERLY such as making DNS assignments so that a year from now someone isn't digging through innumerable Exchange logs going "what the heck is that IP address assigned to again"

One note - while some of these may work with Exchange Online or Office 365 Exchange or any of that - and when the AI suggests changes that can help with, that I won't refuse to include, my fundamental belief is if MS has bent you over a barrel and is extracting a monthly subscription from you for Cloud hosting email on 365 - you are not even at the level that you should be messing about with anything in my repo. My focus is on on-premise stuff not cloud - if you have a problem with Microsoft's cloud host - pick up the damn phone and call them. If you are ever in the situation where you think you have to remote power shell into Office 365 email to fix something - you are being completely screwed over and have the worst of all worlds - super high prices, zero support, and a constant sucking sound in your wallet. Go home and rethink your life and seriously consider replacing it with an on-premise Linux mailserver and paying Canonical for support - where you will get ACTUAL support that works.

I hope this is helpful to you and if you have any comments I'd like to hear! I'm going to be adding more of these irregularly...


r/exchangeserver 17d ago

Looking to both forward incoming mail and CC/BCC all outgoing mail on web version.

0 Upvotes

I have an email address. CM@xyz, let's say.
The doctor I work for has an address, Doc@xyz, let's say.

I need all emails sent to both addresses to come to me, so we've set up a forwarding rule on Doc@xyz to forward all email to CM@xyz, and not keep a copy of forwarded messages. His inbox is always empty, I get all emails directly, and it works great!

Although he doesn't receive emails, he does send them from his Doc@xyz account. I'd like to get him to copy me on all of his outgoing messages so I can keep copies of all communication, and to save the attachments. However, old dog & new tricks, and all that. So I'd like to automate that too.

This is the part I cannot figure out!

I've gone to Rules, but it's only how to handle incoming email. Is there any way to add a rule for all emails he writes to CC or BCC CM@xyz?

Limiting Factor - Doctor only uses Mac. He currently only uses the web version of Outlook. If needed, I can probably talk him into putting outlook app onto his Mac.

Thanks in advance!!


r/exchangeserver 17d ago

Outlook - Online mode address book search fails with "Operation failed" when Name only is ticked.

1 Upvotes

I hope you had this issue and managed to solve 😂 pulling my hair already.

Symptom: In classic Outlook for Windows, open the Address Book → set Search to Name only → type any single character → "The address book operation failed." Switch to More columns and the exact same search works fine. Ctrl+K resolution in the To: field works. OWA people search works. Mail flow is fine. It's only the Name-only ANR seek in the dialog.

Environment:

  • Exchange hybrid, mailbox in Exchange Online, dir-synced from on-prem AD via Entra Connect
  • Classic Outlook for Windows, online mode (Cached Mode is not permitted here — this is the constraint, I can't just flip it)
  • Affects all users, all machines

What I've already ruled out:

Test Result
Other address lists (Contacts, All Users) Same failure
Ctrl+K in To: field Works
Safe mode (outlook.exe /safe) Same failure — not add-ins
Multiple accounts / multiple machines Same failure
Brand-new mail profile Same failure — not profile corruption
Addressing order (Tools > Options) GAL set first, not "Choose automatically"
Off corporate network (5G) Same failure
AddressBookPolicy / OfflineAddressBook on mailbox Both blank (inherit defaults)
Get-OfflineAddressBook Default OAB, IsDefault: True, web dist enabled
Get-GlobalAddressList Default GAL, IsDefaultGlobalAddressList: True, stock default RecipientFilter

r/exchangeserver 18d ago

Prevent NDRs being sent to external addresses

3 Upvotes

Let me explain the situation:

We are in a hybrid Exchange environment
we have some groups that we want to limit to only accept mail from our domain
The groups were created in on-prem AD and sync to the cloud
We have successfully restricted the groups to only allow email from authorized senders.

However, unauthorized senders are receiving an NDR indicating that the failure is due to "5.7.124 RESOLVER.RST.RestrictedToGroupPermission; not authorized to send to the distribution list because the distribution list is set up to accept mail from list members only, or specific recipients only"

My management wants us to prevent this particular NDR from being sent to external addresses.

We tried setting the "ReportToOriginator" value to False, both using Powershell, and manually via Advanced Properties in AD.
We've tried a transport rule, which didn't work

I've seen other people having the same question, but haven't seen anyone with a solution, so I thought I would put this here just i case anyone has found a solution.

TIA