Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

X400 address

Status
Not open for further replies.

jcck2003

IS-IT--Management
Mar 21, 2003
168
US
Hi All:

Exchange 5.5 (not sure if the same case as other version) uses X400 address to send the email internally, Exchange in fact needs this address to send or receive anything, it that correct ?

we have a distribution list includes everyone in the company, somehow the X400 string gets forwarded to an outside party, and replied it back to all the email accounts of the company (even to somebody who has internal only account)

this is a threat to open door to anyone who gets a hold of this X400 string on the internet, so they can send in tons of viruses easily reachable to everyone in the company.

is there a way to disable this string ? or if there is a way to avoid this from happening ?

Thanks
J
 
For starters, you could restrict what users could post to that DL. Restrict the posting permissions to only company employees.

The DL will have both an x400 address and an SMTP address by default. You could also remove the SMTP address for this DL so anyone outside of your exchange organization could not post to it using SMTP.

Is this what for which you are looking?
Dana
 
so if I got to the proerty of the "All Employee" DL

click on "Delivery Restriction"

it gaves me two option, Accept from a list and Reject a from list

should I just put Accept ---> "All Employee" DL

in terms of rejection list, what should I put in there ??

Thanks
JK
 
Thing of it as a matter of including rather than exclusion.

If you have a DL and you want to restrict who can send email to it, include all of the users, or a DL of all of the users that you want to be able to send email to that DL.

You cannot use this to restrict sending email to each individualy mailbox.

i.e. If you put restrictions of who could send email to the "all Employees" DL it will not stop someone from sending email to one user "John Jones" that is a mamber of that DL.

If you want only people on the exchange system (not internet email) just internal users to be able to send to a DL, the easiest way is to remove the SMTP address for that DL.

For someone to use x400, first your exchange server would have to be open to the internet, second, the person trying to send email would have to authenicate using a local domain account, then, and only then could they send to the alias.

So, to make things simple, your exchange server, if connected to the world outside of your company uses SMTP to accept internet email and x400 for internal email only.

So if you want only people inside of the company to send email to the DL, remove it's SMTP address.

(I am assuming that all of your internal users are Outlook users, and not using Eudora, or any POP/SMTP email programs to get email.)

I hope this helps,
Dana
 
Hi Dana:

yes we do want internal people only to get to that "All Employees" DL, want to diable its incoming from any outside email, and I have already delete its SMTP address, but the message would still come in

yes our Xchange server is connected to SMTP/MX record by an ISP

I created a dummy DL to test today, delete its SMTP address and every address except the x400, the email would still come in from an outside address without authenicate in our network(I just used a yahoo account), then the second time I went into the Delivery Restriction tab of the property of that dummy DL, set "Accept message from" choose to list ... then put down everyone in the company (all DLs and all individual internal mailboxes) and hit apply. and send a second email through yahoo and the second email still come through from the X400 address



Is there a permission setting I can set in the DL so I can set this up ??

thanks
J

 
J,
Your exchange server should not be setup to allow sending email to an x400 address without authentication.

To set the permissions on a DL, in Exchange administrator, go to properties of the DL and on the Delivery Restrictions tab, add the DL or individualy users that you want to be able to send to the DL.

If you send email from your Yahoo account to a DL at your company, it uses "Internet email" or SMTP.

Remember if you have more than one mail server at your site and changes to an account or DL will need time to be replicated to all servers.

If you give me the address of your dummy DL, I will send you a piece of email to that address. It definitely should bounce if you deleted the SMTP address. If you want to take this off-line my email is dana@(no-spam)narus.com (remove "no spam" from the adress.

 
Hi Dana:

thanks for your reply
I just sent you an email with the DL address, I have already deleted its SMTP address,

please let me know if this is done correctly

J

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top