Consider the following:
An Exchange Dynamic Distribution Group has a valid recipient filter, and the filter generates the desired resultant set of recipients with the following PowerShell command:
Get-Recipient - RecipientPreviewFilter $(Get-DynamicDistributionGroup "name").RecipientFilter
However, when a user sends a message to the group, no messages are delivered, and the sender does not receive an NDR.
One possible cause of this issue is a property of the dynamic distribution group called RecipientContainer. This is similar to the SearchBase attribute of the Get-ADUser cmdlet: it specifies the container in which to apply the RecipientFilter. Therefore, the RecipientContainer must be the OU (Or a parent of) in which the desired users are stored.
More info here: https://www.corelan.be/index.php/2008/11/05/dynamic-distribution-lists-not-working-as-expected-0-recipients-during-mail-routing/
Like most sysadmins, I receive notifications from end users about SPAM showing up in their inbox. While not all spam can be avoided, we can deal with it. I wanted to lessen the impact of already delivered spam and potentially avert a crisis if the same phishing email is sent to all 1500 mailboxes, so I whipped up this script to search out and destroy these messages from my Exchange environment:
$Subject = “About your last transaction”
$StartDate = $(‘1/1/2015’)
$BodyLanguage = “sellam.fr”
$TargetMailbox = “spamdump”
$TargetFolder = “WHD2918”
$Search = [scriptblock]::Create(“Received>=`”$StartDate`” and Subject:`”$Subject`” and `”$BodyLanguage`””)
Get-Mailbox -ResultSize Unlimited | Search-Mailbox -SearchQuery $Search -targetmailbox $TargetMailbox -targetfolder $TargetFolder -loglevel full -logonly
Note the last flag in the last line of the script: “-logonly.” Be very careful to run the command with this command the first go-round. This ensures that the query you specify does not grab messages that it shouldn’t (and you wind up deleting everyone’s entire mailbox). The result of logonly is an excel file in the target mailbox with the headers of the resultant messages.
After reviewing the messages, replace -logonly with -deletecontent. This will actually move the messages from the users’ mailboxes into the target mailbox.
If you want to modify the query, take a look into how Search-Mailbox actually works. Search-Mailbox uses KQL, so be sure to brush up on the syntax. If you’ve beocme accustomed to the powershell boolean operators such as “-and,” You’ll be unpleasantly surprised when you learn that the same operator will evaluate to “not and” in KQL