Exchange Online Office 365 Hybrid configuration connectivity problems – Must issue a STARTTLS command first

We noticed that we were not sending any Email from our On-Premise Exchange Server to the Exchange Online Server so I checked the queue.

In the EMC go to the Toolbox and click on Queue Viewer.

In the Queue Viewer I can see that there are a lot of Emails waiting to be sent out.

The error Message that I was getting was:

“451 5.7.3 Must issue a STARTTLS command First.”

I also checked the connectivity logs.

C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\Connectivity

Here I was seeing the following error.

SMTP,aegpsgmbh.mail.onmicrosoft.com,+,DnsConnectorDelivery XXXXXXXX-11c3-463f-a23f-c732f013f3d7;QueueLength=415

SMTP,aegpsgmbh.mail.onmicrosoft.com,>,”company-mail-onmicrosoft-com.mail.eo.outlook.com[XXX.XXX.XXX.87, XXX.XXX.XXX.23]”

SMTP,aegpsgmbh.mail.onmicrosoft.com,>,Established connection to XXX.XXX.XXX.87

SMTP,aegpsgmbh.mail.onmicrosoft.com,-,Messages: 0 Bytes: 0 (Attempting next target)

SMTP,aegpsgmbh.mail.onmicrosoft.com,+,DnsConnectorDelivery XXXXXXXX-11c3-463f-a23f-c732f013f3d7;QueueLength=414

SMTP,aegpsgmbh.mail.onmicrosoft.com,>,Established connection to XXX.XXX.XXX.23

SMTP,aegpsgmbh.mail.onmicrosoft.com,-,Messages: 0 Bytes: 0 (Retry : Must issue a STARTTLS command first)

I also noticed that there were other queues not sending out emails and also logging that the IP address was blacklisted. So I checked my IP address against blacklist providers

http://mxtoolbox.com/blacklists.aspx

The IP address was blacklisted, so I went about getting it removed.

To get the IP address removed from Microsoft you need to send an email to the following addresses.

I also went about whitelisting my IP address on the Exchange Online server which to be honest is something that we should have done in the first place.

To do this go to the Exchange Online Admin Center / Protection / Connection Filter and edit the Default profile. Under Connection filtering add your Public IP address of your On-Premise Exchange Server.

After a 10 minutes or so, you should check your Queue again and should see that the Emails start being sent to the Online exchange Server.