Exchange message tracking log

Message tracking log


Get-MessageTrackingLog -Start "04/08/2019 14:00:00" -End "04/08/2019 15:00:59" -Sender "qr-alert@b.co.il" | sort timestamp | format-list

 

 

Get-Message -Filter {FromAddress -like "*qr-alert@b.co.il"} | format-list

 

 

Get-MessageTrackingLog -recipient "dani@b.co.il" -sender "hayt@c.co.il" -eventid deliver -start 01/26/2020 -end 01/27/2020 | select *

 

 

Get emails with deliver status only

Get-MessageTrackingLog -recipient "dani@d.co.il" -start 01/01/2020 -end 02/09/2020 -eventid deliver | sorttimestamp

Event types in the message tracking log

Various event types in the event-id field are used to classify the message events in the message tracking log. Some message events appear in only one type of message tracking log file, and some message events appear in all types of message tracking log files. The events types that are used to classify each message event are explained in the following table.

 

Event name

Description

AGENTINFO

This event is used by transport agents to log custom data.

BADMAIL

A message submitted by the Pickup directory or the Replay directory that can't be delivered or returned.

CLIENTSUBMISSION

A message was submitted from the Outbox of a mailbox.

DEFER

Message delivery was delayed.

DELIVER

A message was delivered to a local mailbox.

DELIVERFAIL

An agent tried to deliver the message to a folder that doesn't exist in the mailbox.

DROP

A message was dropped without a delivery status notification (also known as a DSN, bounce message, non-delivery report, or NDR). For example: 

• Completed moderation approval request messages. 

• Spam messages that were silently dropped without an NDR.

DSN

A delivery status notification (DSN) was generated.

DUPLICATEDELIVER

A duplicate message was delivered to the recipient. Duplication may occur if a recipient is a member of multiple nested distribution groups. Duplicate messages are detected and removed by the information store.

DUPLICATEEXPAND

During the expansion of the distribution group, a duplicate recipient was detected.

DUPLICATEREDIRECT

An alternate recipient for the message was already a recipient.

EXPAND

A distribution group was expanded.

FAIL

Message delivery failed. Sources include SMTP, DNS, QUEUE, and ROUTING.

HADISCARD

A shadow message was discarded after the primary copy was delivered to the next hop. For more information, see Shadow redundancy in Exchange Server.

HARECEIVE

A shadow message was received by the server in the local database availability group (DAG) or Active Directory site.

HAREDIRECT

A shadow message was created.

HAREDIRECTFAIL

A shadow message failed to be created. The details are stored in the source-context field.

INITMESSAGECREATED

A message was sent to a moderated recipient, so the message was sent to the arbitration mailbox for approval. For more information, see Moderated Transport.

LOAD

A message was successfully loaded at boot.

MODERATIONEXPIRE

A moderator for a moderated recipient never approved or rejected the message, so the message expired. For more information about moderated recipients, see Moderated Transport.

MODERATORAPPROVE

A moderator for a moderated recipient approved the message, so the message was delivered to the moderated recipient.

MODERATORREJECT

A moderator for a moderated recipient rejected the message, so the message wasn't delivered to the moderated recipient.

MODERATORSALLNDR

All approval requests sent to all moderators of a moderated recipient were undeliverable, and resulted in non-delivery reports (also known as NDRs or bounce messages).

NOTIFYMAPI

A message was detected in the Outbox of a mailbox on the local server.

NOTIFYSHADOW

A message was detected in the Outbox of a mailbox on the local server, and a shadow copy of the message needs to be created.

POISONMESSAGE

A message was put in the poison message queue or removed from the poison message queue.

PROCESS

The message was successfully processed.

PROCESSMEETINGMESSAGE

A meeting message was processed by the Mailbox Transport Delivery service.

RECEIVE

A message was received by the SMTP receive component of the transport service or from the Pickup or Replay directories (source: SMTP), or a message was submitted from a mailbox to the Mailbox Transport Submission service (source: STOREDRIVER).

REDIRECT

A message was redirected to an alternative recipient after an Active Directory lookup.

RESOLVE

A message's recipients were resolved to a different email address after an Active Directory lookup.

RESUBMIT

A message was automatically resubmitted from Safety Net. For more information, see Safety Net in Exchange Server.

RESUBMITDEFER

A message resubmitted from Safety Net was deferred.

RESUBMITFAIL

A message resubmitted from Safety Net failed.

SEND

A message was sent by SMTP between transport services.

SUBMIT

The Mailbox Transport Submission service successfully transmitted the message to the Transport service. For SUBMIT events, the source-context property contains the following details: 

MDB: The mailbox database GUID. 

Mailbox: The mailbox GUID. 

Event: The event sequence number. 

MessageClass: The type of message. For example, IPM.Note. 

CreationTime: Date-time of the message submission. 

ClientType: For example, User, OWA, or ActiveSync.

SUBMITDEFER

The message transmission from the Mailbox Transport Submission service to the Transport service was deferred.

SUBMITFAIL

The message transmission from the Mailbox Transport Submission service to the Transport service failed.

SUPPRESSED

The message transmission was suppressed.

THROTTLE

The message was throttled.

TRANSFER

Recipients were moved to a forked message because of content conversion, message recipient limits, or agents. Sources include ROUTING or QUEUE.

Source values in the message tracking log

The values in the source field in the message tracking log indicate the transport component that's responsible for the message tracking event. The following table describes the values of the source field.

 

Source value

Description

ADMIN

The event source was human intervention. For example, an administrator used Queue Viewer to delete a message, or submitted message files using the Replay directory.

AGENT

The event source was a transport agent.

APPROVAL

The event source was the approval framework that's used with moderated recipients. For more information, see Moderated Transport.

BOOTLOADER

The event source was unprocessed messages that exist on the server at boot time. This is related to the LOAD event type.

DNS

The event source was DNS.

DSN

The event source was a delivery status notification (also known as a DSN, bounce message, non-delivery report, or NDR).

GATEWAY

The event source was a Foreign connector. For more information, see Foreign Connectors.

MAILBOXRULE

The event source was an Inbox rule. For more information, see Inbox rules.

MEETINGMESSAGEPROCESSOR

The event source was the meeting message processor, which updates calendars based on meeting updates.

ORAR

The event source was an Originator Requested Alternate Recipient (ORAR). You can enable or disable support for ORAR on Receive connectors using the OrarEnabled parameter on the New-ReceiveConnectoror Set-ReceiveConnector cmdlets.

PICKUP

The event source was the Pickup directory. For more information, see Pickup Directory and Replay Directory.

POISONMESSAGE

The event source was the poison message identifier. For more information about poison messages and the poison message queue, see Queues and messages in queues

PUBLICFOLDER

The event source was a mail-enabled public folder.

QUEUE

The event source was a queue.

REDUNDANCY

The event source was Shadow Redundancy. For more information, see Shadow redundancy in Exchange Server.

ROUTING

The event source was the routing resolution component of the categorizer in the Transport service.

SAFETYNET

The event source was Safety Net. For more information, see Safety Net in Exchange Server.

SMTP

The message was submitted by the SMTP send or SMTP receive component of the transport service.

STOREDRIVER

The event source was a MAPI submission from a mailbox on the local server.

 

 

https://docs.microsoft.com/en-us/exchange/mail-flow/transport-logs/message-tracking?view=exchserver-2019