Reduce SPAM and increase security with SMTP Submission over Port 587

Exchange server 2007 provides higher security and less SPAM potential by elimination authenticated mail over SMTP port 25.    This leaves us without the ability to relay mail from other SMTP servers without the following tips.

Here are some setup tips on setting up SMTP relay over port 587 securely.

After setting up your network with a back-end Exchange 2007 Hub Transport/Client Access/Mailbox server and an isolated Exchange 2007 Edge Transport server in a DMZ or separate internal network, try setting up an IMAP connection to the Exchange Client Access server.  Since all incoming mail traffic is supposed to flow through the Edge Transport server, you set up that as the endpoint for your outgoing SMTP server in your mail client like Microsoft Outlook or Mozilla Thunderbird, but no matter what you do, it just won’t work without authentication.  The Edge Transport server is not (or at least it’s not supposed to be) a member of the domain, and therefore cannot authenticate the user.

One way to fix this is to set your firewall(s) to pass SMTP Submission traffic to the back-end Client Access server (CAS).    Mail will  be sent first to the back end Exchange Client Access server for authentication, and then be forwarded on to the front end server for external delivery.

Also, don’t forget to to check off the TLS or SSL security option and change the outgoing SMTP port number to 587 for SMTP Submission, rather than port 25 for standard SMTP traffic.  And now, you should be sending mail securely.