I have encountered a very strange issue that I am stumped on. I have a user on my domain that sent an email to another user on the same domain. The email was sent successfully and I can see in the exim logs that the email was delivered using the virtual_user which I assume is for internal emails.
However, about five hours later the original sender received a non delivery report from Microsoft stating that her email was unable to be delivered. The strange part is the address listed in the NDR is on an external O365 domain that I have never seen before. I've searched the logs for any matches and am unable to find it. I've also checked both users computers and can not find any sort of forwarding rule.
Also in the Microsoft NDR it shows the message hops which starts from the sender's IP address to our mail server IP address using SMTP, and then a second hop with both the from and destination being my mail server address using LMTP which I would assume is delivering the mail to the other internal user.
The next hop shows the hop going from 127.0.1.1 to a Outlook SMTP server based in Europe. This relay time takes almost 7 hours before it ultimately fails and sends back the NDR.
I am at a loss as to how an email that is being sent and received from internal users would even be received by any external email server, let alone one I have never seen before and can find no information on. The NDR also has a copy of the original email that does not contain the email address of the Office365 user at all.
If anyone has any ideas I would greatly appreciate them!
However, about five hours later the original sender received a non delivery report from Microsoft stating that her email was unable to be delivered. The strange part is the address listed in the NDR is on an external O365 domain that I have never seen before. I've searched the logs for any matches and am unable to find it. I've also checked both users computers and can not find any sort of forwarding rule.
Also in the Microsoft NDR it shows the message hops which starts from the sender's IP address to our mail server IP address using SMTP, and then a second hop with both the from and destination being my mail server address using LMTP which I would assume is delivering the mail to the other internal user.
The next hop shows the hop going from 127.0.1.1 to a Outlook SMTP server based in Europe. This relay time takes almost 7 hours before it ultimately fails and sends back the NDR.
I am at a loss as to how an email that is being sent and received from internal users would even be received by any external email server, let alone one I have never seen before and can find no information on. The NDR also has a copy of the original email that does not contain the email address of the Office365 user at all.
If anyone has any ideas I would greatly appreciate them!
Last edited by a moderator: