XFOR: Connection Access Control Feature Does Not Block For Each Domain (251457)



The information in this article applies to:

  • Microsoft Exchange 2000 Server

This article was previously published under Q251457

SYMPTOMS

When you configure connection access to the Simple Mail Transfer Protocol (SMTP) server, the domain that you specify to be blocked may still be able to connect to the SMTP server. This connection occurs even though Domain Name System (DNS) reverse lookup is configured correctly.

For example, if you configure your SMTP server to block connections from the domain "microsoft.com" (by opening the properties of the virtual SMTP server, clicking the Access tab, clicking Connection, clicking All except the list below, and then adding the domain "microsoft.com"), a computer named server.microsoft.com may still be able to connect to your server.

CAUSE

This problem can occur if the blocked domain entry is not configured properly.

WORKAROUND

To work around this problem, make sure that the entry is formatted as follows:

*.domain.com

For the example in the "Symptoms" section of this article, the correct entry is the following:

*.microsoft.com

The following entry also works:

server.microsoft.com

STATUS

Microsoft has confirmed that this is a problem in Microsoft Exchange 2000 Server.

Modification Type:MinorLast Reviewed:4/25/2005
Keywords:kbbug kbnofix KB251457