Comments on: MX Records for Exchange Hybrid Deployments https://practical365.com/mx-records-for-exchange-hybrid-deployments/ Practical Office 365 News, Tips, and Tutorials Mon, 16 Sep 2019 10:52:53 +0000 hourly 1 https://wordpress.org/?v=6.6.1 By: Abdulrehman Altaf https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-226502 Mon, 16 Sep 2019 10:52:53 +0000 https://www.practical365.com/?p=10952#comment-226502 Hi Paul,
we have exchange 2016 on prem and outlook2013 auto discover configure after the mailbox migration to exchange online. we will point the MX record to O365.
users need to reconfigure mailbox again on pcs ? and what about the mailbox configured on mobile devices ?

]]>
By: raguvaran https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-221679 Fri, 02 Aug 2019 15:54:26 +0000 https://www.practical365.com/?p=10952#comment-221679 Hi Paul,
IF MX Pointed to On-prem.Then how can we go for DKIM,Dmarc in on-prem exchange server.

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_156356'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_156356"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-156356 Wed, 29 Nov 2017 23:07:39 +0000 https://www.practical365.com/?p=10952#comment-156356 In reply to Rick.

It depends. Most likely yes, the HCW will be re-run if you need to turn off centralized transport or adjust the connectors. There’s some more detailed documentation on TechNet now for the various mail flow scenarios:

https://technet.microsoft.com/en-us/library/jj937232(v=exchg.150).aspx

]]>
By: Rick https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-156343 Wed, 29 Nov 2017 13:20:33 +0000 https://www.practical365.com/?p=10952#comment-156343 Hi.

Ok so we have scenario 1 and has been working fine for a year. We now want to move to scenario 2.

Updating the MX record is fairly straight forward but do we need to make changes to the hybrid setup wizard to tell if primary mail flow is now going to O365?

Thanks
Rick.

]]>
By: Armando https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-152984 Mon, 18 Sep 2017 16:19:56 +0000 https://www.practical365.com/?p=10952#comment-152984 Hi Paul,
Thanks for article, i have a question and a problem with my configuration:

We setup a hybrid environment with Exchange 2010, however onpremises users cant send email to some destinations, outlook, google and majority ar ok but with few recipients i got error(O365 accounts does not have this problem):

451 4.4.0 Primary target IP address responded with: “421 bosimpinc14 bizsmtp Temporarily rejected. Reverse DNS for xxx.xx.xx.xx failed..” Attempted failover to alternate host, but that did not succeed. Either there are no alternate hosts, or delivery failed to all alternate hosts.

i am using an edge to route external onpremises mail.

My DNS configurations are:

MX> Actual record  10  @  mail.messaging.microsoft.com.  3600
SPF> Actual record  @  v=spf1 ip4:external ip mx include:spf.protection.outlook.com ~all
(external ip is mail.domain.com, my onpremises owa is, solmail.domain.com)

hope you can help me

thanks
Armando

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_45478'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_45478"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-45478 Tue, 21 Feb 2017 22:25:34 +0000 https://www.practical365.com/?p=10952#comment-45478 In reply to Al.

“The email came to my outlook inbox but when I log into Office 365 web mail there is nothing there.”

What is Outlook connecting to? Your on-premises server, or a cloud mailbox?

]]>
By: Al https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-45325 Tue, 21 Feb 2017 17:03:03 +0000 https://www.practical365.com/?p=10952#comment-45325 Hi Paul,

Based on your article here we are setup similar to scenario # 3. For some reason the routing isn’t working properly. Our on-premise Exchange 2010 functions but the Office 365 test mailbox is only able to send out but not receive. I sent a test to myself internally and externally. The email came to my outlook inbox but when I log into Office 365 web mail there is nothing there. The MX record points to our Barracuda Spam filter appliance. I do have port 25 enabled inbound / outbound on our firewall to allow the block of Microsoft IP addresses. Thanks in advance for any help you could provide.

Al

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_23334'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_23334"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-23334 Sat, 19 Mar 2016 09:47:35 +0000 https://www.practical365.com/?p=10952#comment-23334 In reply to Jean.

EOP is licensed per user. Beyond that I can’t give you licensing advice. You should speak to your license reseller to determine the correct licensing for your situation.

]]>
By: Jean https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-23333 Fri, 18 Mar 2016 16:33:47 +0000 https://www.practical365.com/?p=10952#comment-23333 Thx for this article

If I want to use “SCENARIO 2 – MX RECORDS POINTING TO OFFICE 365” with 1000 mailboxes on-premise and 50 mailboxes in Office 365 (for VIP only for example)

Do I have to pay “only” 50 Office 365 subscription (for my 50 Office 365 mailboxes) with a mailflow cleaning done by EOP for my 1050 mailboxes or do I have to pay something else to MS ?
https://products.office.com/en-us/exchange/microsoft-exchange-online-protection-email-filter-and-anti-spam-protection-email-security-email-spam

Or does MS only apply EOP on my 50 Office 365 mailboxes and redirect to my Exchange on-premise servers the native mailflow (not cleaned) for my 1000 on-premise mailboxes ?

thx in advance

Jean

]]>
By: Ryan https://practical365.com/mx-records-for-exchange-hybrid-deployments/#comment-23332 Thu, 03 Dec 2015 16:40:59 +0000 https://www.practical365.com/?p=10952#comment-23332 @Brandon makes a good point. It was surprising (and somewhat disconcerting) to learn this was happening. I’m pretty sure it applies to both Scenario 1 and Scenario 3 (really, any scenario where the MX records don’t point to Office 365/EOP). Basically, if you have Exchange Hybrid configured and *think* you have configured it so that all inbound mail routes first through something other than O365, that is likely not the case. I also think there is some danger in situations were you may not have completely/correctly configured your Hybrid deployment for mail flow that some mail won’t get through. It’s a mail flow situation that isn’t necessarily obvious/noticeable until you start digging into O365 mail traces and email headers but, could be pretty important – especially to organizations that have strict compliance requirements. As Brandon mentions, there ARE workarounds but, those aren’t the most obvious either.

Agree with Brandon that it is ‘pretty goofy’ and, more importantly, isn’t really documented anywhere that I could find (by Microsoft or the community).

]]>