Monitoring Benefit
The External Mail Flow check verifies a full round trip: that a message can be sent from an internal Exchange mailbox out to an external mail domain, and that a message from that external domain can be received back.
Internal mail flow tests stop at your own boundary. This one covers everything past it — your outbound path, the external provider, your inbound path, and the filtering in between. It is the check that tells you customers can actually reach you.
How the test is built
The test uses two mailboxes: an internal Exchange mailbox, and an external mailbox at a public mail provider configured with an automatic forwarding rule that returns messages to the internal one. Understanding that shape makes the failures far easier to read, because the round trip can break at either end for quite different reasons.
How do we verify the monitoring test results?
1. Check the internal mailbox. Open it in Outlook Web App and confirm messages from the external test mailbox are arriving.
2. Check the external mailbox. Confirm it is receiving the outbound test messages, and that its auto-forward rule is still enabled and still pointed at the internal address. Providers disable forwarding rules on their own — after a password change, a security review, or a policy change — and this is a frequent cause of a test that fails with nothing wrong at the Exchange end.
3. Establish which direction failed. Outbound and inbound have different causes. If outbound messages are reaching the external mailbox but nothing comes back, the problem is the forwarding rule or your inbound path, not your outbound one.
Common warning or error results, and potential solutions
| Result | Potential solution |
| Spam confidence level (SCL) higher than expected | The returning message is being treated as spam by your own filtering. Review the SCL threshold and the anti-spam policy applied to the internal test mailbox — forwarded mail is more likely to score highly because forwarding breaks sender authentication. |
| Inbound message not received | Check the external mailbox's forwarding rule before anything else. Also confirm the external provider has not quarantined or rate-limited the message. |
| Outbound leaves but nothing returns | Your outbound path is fine. Work on the external mailbox and your inbound path — forwarding rule, provider-side filtering, then your own gateway. |
| Started failing with no change at your end | External providers change their forwarding, authentication and security policies without notice. Confirm the external test account is still fully functional and its credentials still valid. |
| Intermittent failures | Usually delivery latency rather than loss, particularly where greylisting or rate limiting is involved. Check whether the messages arrive late rather than not at all. |
| Results are stale rather than failing | If several unrelated checks stopped updating at the same moment, look at the ENow SQL database connection rather than at mail flow. |
Monitoring page. The detail behind this indicator is served by the ENow web server at:
http://localhost:20080/MailscapeWeb/ExternalMailFlow.aspx?server=<SERVER>
Replace localhost with the web server's host name if you are browsing from elsewhere, 20080 with your own port if it was changed at installation, and <SERVER> with the monitored server you are investigating.
Reference. Spam confidence level (SCL).
Comments
0 comments
Article is closed for comments.