RE: How to block incoming/external SMTP e-mail easily for a Group of u



Hi Ed,

Thank you for posting here!

It seems that you would like to prevent certain users from
sending/receiving Internet (external) emails. If I'm off base, please let
me know.

Prevent receiving Internet emails
------------------------------
To restrict users from receiving Internet e-mail messages in Exchange
Server, create two SMTP addresses, one is <username>@domain.com and
<username>@domain.local. Then, the users who have the <username>@domain.com
address can receive Internet emails, but the users who only have the
<username>@domain.local address can only receive internal emails. To do
this:

1. Start Exchange System Manager and expand Recipients -> Recipient
Policies, right-click the default policy, and then click Properties.
2. Click the E-Mail Addresses tab.
3. Click New, click SMTP Address, and then click OK.
4. In the Address box, type @domain.local, and then click OK.
5. On the E-Mail Addresses tab, click to select the check box next to the
@domain.local that you just added.
6. Click the new @domain.local address, and then click Set as Primary.
7. Click OK. Note: If you are prompted to update all of the corresponding
recipient e-mail addresses to match the changes that you made, click Yes to
apply the changes you made to the recipient policy to the recipients that
are associated with the policy. If you set the new e-mail address as the
primary address, the other e-mail addresses of that type automatically
become secondary addresses.

8. Right click to run "Update Now" on the Recipient Update Service (Domain).
9. Open Active Directory Users and Computers -> Users. Double click to open
the specific users that you want to reject from receiving Internet email,
and then remove the @domain.com under the E-mail Address tab.

Note: If you have many users to restrict from receiving Internet email, you
can create a new Universal Group in ADUC and then add all the restrict
users into the specific group. Then create a new Recipient Policy to set
the @domain.local as the default SMTP Address, and then apply the new
Recipient Policy to the specific group to accomplish this goal.

For more detailed information, please refer to the following Microsoft KB
articles which also apply to Exchange Server 2003.

327762 HOW TO: Selectively Permit Access to Internet Messages by Modifying
http://support.microsoft.com/?id=327762

319201 HOW TO: Use Recipient Policies to Control E-mail Addresses in
Exchange
http://support.microsoft.com/?id=319201

Prevent sending Internet emails
------------------------------
If we want to prevent some users from sending email to external addresses,
we can configure an SMTP Connector to achieve this. After this we need to
modify a CheckConnectorRestrictions registry key to make this restriction
take effect. To do this:

1. Create an SMTP Connector in Routing Groups -> First Routing Group ->
Connectors.
2. Access the Connector properties page and see the "Delivery Restrictions"
tab.
3. Under By default, messages from everyone are, make sure that Accepted is
selected.
4. Under Reject messages from, click Add.
5. In the Select Recipient dialog box, click to add users, contacts, or
groups. All other senders are accepted automatically.
6. By default, Delivery restrictions are not functional until set in the
registry.

(1) Start Registry Editor.
(2) Locate and click the following registry key:
HKEY_LOCAL_MACHINE/System/CurrentControlSet/Services/Resvc/Parameters/
(3) On the Edit menu, click Add Value, and then add the following registry
value:

Value Name: CheckConnectorRestrictions
Data Type: REG_DWORD
Radix: Hexadecimal
Value: 1

(4) Quit Registry Editor.
(5) Restart the Microsoft Exchange Routing Engine service and the Simple
Mail Transfer Protocol (SMTP) services for this change to take effect.

Please see the following Microsoft KB articles for more information.

XCON: Connector Delivery Restrictions Do Not Work Correctly
http://support.microsoft.com/?id=277872

How to Configure the SMTP Connector in Exchange 200x
http://support.microsoft.com/?id=265293

I hope the information above is helpful.

If anything in my post is unclear, feel free to let me know. I'm looking
forward to your reply.

Have a good day!

Thanks & regards,

Winfred Weng
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.

=====================================================
Business-Critical Phone Support (BCPS) provides you with technical phone
support at no charge during critical LAN outages or "business down"
situations. This benefit is available 24 hours a day, 7 days a week to all
Microsoft technology partners in the United States and Canada.

This and other support options are available here:

BCPS:
https://partner.microsoft.com/US/technicalsupport/supportoverview/40010469
Others: https://partner.microsoft.com/US/technicalsupport/supportoverview/

If you are outside the United States, please visit our International
Support page:
http://support.microsoft.com/common/international.aspx
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.


--------------------
>Thread-Topic: How to block incoming/external SMTP e-mail easily for a
Group of u
>thread-index: AcXZr5gQR56R+ls+SOSFxTI/FW4NvQ==
>X-WBNR-Posting-Host: 208.181.21.221
>From: =?Utf-8?B?ZWRAbGVoaWdo?= <ed@xxxxxxxxxx>
>Subject: How to block incoming/external SMTP e-mail easily for a Group of u
>Date: Tue, 25 Oct 2005 15:01:04 -0700
>Lines: 11
>Message-ID: <9C8804F6-AC88-4F44-8C65-887679AB7269@xxxxxxxxxxxxx>
>MIME-Version: 1.0
>Content-Type: text/plain;
> charset="Utf-8"
>Content-Transfer-Encoding: 7bit
>X-Newsreader: Microsoft CDO for Windows 2000
>Content-Class: urn:content-classes:message
>Importance: normal
>Priority: normal
>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
>Newsgroups: microsoft.public.exchange2000.general
>NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
>Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA02.phx.gbl!TK2MSFTNGXA03.phx.gbl
>Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.exchange2000.general:15107
>X-Tomcat-NG: microsoft.public.exchange2000.general
>
>We have a number of accounts in use by hourly people, for which there is
>business requirement that they be able to send email internally. There is
>also a business requirement that these people not be able to receive
external
>SMTP email. In the Exchange 5.5 world, we would simply remove the SMTP
>address from the mailbox. However, that cannot be done in Exchange 2003.
>How can we meet this business requirement if the user has an Exchange 2003
>mailbox?
>
>Thanks in advance,
>
>Ed
>

.



Relevant Pages

  • Re: Exchange not receiving email from Internet
    ... Recieved email for that domain from internet. ... I understand that your exchange unable to ... permission to send to this recipient". ... The Exchange server Directory Access tab error may not related to ...
    (microsoft.public.windows.server.sbs)
  • RE: send mail
    ... out emails with exchange using DNS. ... if we want to send internet e-mail with the internal exchange ... 825763 How to configure Internet access in Windows Small Business Server ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange not receiving email from Internet
    ... I understand that your exchange unable to ... permission to send to this recipient". ... The Exchange server Directory Access tab error may not related to ... How to configure Internet access in Windows Small Business Server 2003 ...
    (microsoft.public.windows.server.sbs)
  • Re: e-mail messages stop in categorizer problem
    ... Based on my experience, since this is a SBS server, you can simply run ... In the right pane, click "Connect to the Internet", and then click ... Open the Exchange System Manager, go to Recipients -> Recipient ...
    (microsoft.public.windows.server.sbs)
  • Re: Removing primary email domain?
    ... already directed offsite, since a few users have offsite POP boxes. ... automatically apply recipient policies. ... couple of other internet domains ... it to Exchange mailboxes via a long list of Routing Rules in the POP3 ...
    (microsoft.public.windows.server.sbs)

Quantcast