Message tracking log
Get-MessageTrackingLog -Start "04/08/2019 14:00:00" -End "04/08/2019 15:00:59" -Sender "qr-alert@b.co.il" | sort timestamp | format-list
Get-Message -Filter {FromAddress -like "*qr-alert@b.co.il"} | format-list
Get-MessageTrackingLog -recipient "dani@b.co.il" -sender "hayt@c.co.il" -eventid deliver -start 01/26/2020 -end 01/27/2020 | select *
Get emails with deliver status only
Get-MessageTrackingLog -recipient "dani@d.co.il" -start 01/01/2020 -end 02/09/2020 -eventid deliver | sorttimestamp
Event types in the message tracking log
Various event types in the event-id field are used to classify the message events in the message tracking log. Some message events appear in only one type of message tracking log file, and some message events appear in all types of message tracking log files. The events types that are used to classify each message event are explained in the following table.
|
Event name |
Description |
|
AGENTINFO |
This event is used by transport agents to log custom data. |
|
BADMAIL |
A message submitted by the Pickup directory or the Replay directory that can't be delivered or returned. |
|
CLIENTSUBMISSION |
A message was submitted from the Outbox of a mailbox. |
|
DEFER |
Message delivery was delayed. |
|
DELIVER |
A message was delivered to a local mailbox. |
|
DELIVERFAIL |
An agent tried to deliver the message to a folder that doesn't exist in the mailbox. |
|
DROP |
A message was dropped without a delivery status notification (also known as a DSN, bounce message, non-delivery report, or NDR). For example: • Completed moderation approval request messages. • Spam messages that were silently dropped without an NDR. |
|
DSN |
A delivery status notification (DSN) was generated. |
|
DUPLICATEDELIVER |
A duplicate message was delivered to the recipient. Duplication may occur if a recipient is a member of multiple nested distribution groups. Duplicate messages are detected and removed by the information store. |
|
DUPLICATEEXPAND |
During the expansion of the distribution group, a duplicate recipient was detected. |
|
DUPLICATEREDIRECT |
An alternate recipient for the message was already a recipient. |
|
EXPAND |
A distribution group was expanded. |
|
FAIL |
Message delivery failed. Sources include SMTP, DNS, QUEUE, and ROUTING. |
|
HADISCARD |
A shadow message was discarded after the primary copy was delivered to the next hop. For more information, see Shadow redundancy in Exchange Server. |
|
HARECEIVE |
A shadow message was received by the server in the local database availability group (DAG) or Active Directory site. |
|
HAREDIRECT |
A shadow message was created. |
|
HAREDIRECTFAIL |
A shadow message failed to be created. The details are stored in the source-context field. |
|
INITMESSAGECREATED |
A message was sent to a moderated recipient, so the message was sent to the arbitration mailbox for approval. For more information, see Moderated Transport. |
|
LOAD |
A message was successfully loaded at boot. |
|
MODERATIONEXPIRE |
A moderator for a moderated recipient never approved or rejected the message, so the message expired. For more information about moderated recipients, see Moderated Transport. |
|
MODERATORAPPROVE |
A moderator for a moderated recipient approved the message, so the message was delivered to the moderated recipient. |
|
MODERATORREJECT |
A moderator for a moderated recipient rejected the message, so the message wasn't delivered to the moderated recipient. |
|
MODERATORSALLNDR |
All approval requests sent to all moderators of a moderated recipient were undeliverable, and resulted in non-delivery reports (also known as NDRs or bounce messages). |
|
NOTIFYMAPI |
A message was detected in the Outbox of a mailbox on the local server. |
|
NOTIFYSHADOW |
A message was detected in the Outbox of a mailbox on the local server, and a shadow copy of the message needs to be created. |
|
POISONMESSAGE |
A message was put in the poison message queue or removed from the poison message queue. |
|
PROCESS |
The message was successfully processed. |
|
PROCESSMEETINGMESSAGE |
A meeting message was processed by the Mailbox Transport Delivery service. |
|
RECEIVE |
A message was received by the SMTP receive component of the transport service or from the Pickup or Replay directories (source: SMTP), or a message was submitted from a mailbox to the Mailbox Transport Submission service (source: STOREDRIVER). |
|
REDIRECT |
A message was redirected to an alternative recipient after an Active Directory lookup. |
|
RESOLVE |
A message's recipients were resolved to a different email address after an Active Directory lookup. |
|
RESUBMIT |
A message was automatically resubmitted from Safety Net. For more information, see Safety Net in Exchange Server. |
|
RESUBMITDEFER |
A message resubmitted from Safety Net was deferred. |
|
RESUBMITFAIL |
A message resubmitted from Safety Net failed. |
|
SEND |
A message was sent by SMTP between transport services. |
|
SUBMIT |
The Mailbox Transport Submission service successfully transmitted the message to the Transport service. For SUBMIT events, the source-context property contains the following details: MDB: The mailbox database GUID. Mailbox: The mailbox GUID. Event: The event sequence number. MessageClass: The type of message. For example, IPM.Note. CreationTime: Date-time of the message submission. ClientType: For example, User, OWA, or ActiveSync. |
|
SUBMITDEFER |
The message transmission from the Mailbox Transport Submission service to the Transport service was deferred. |
|
SUBMITFAIL |
The message transmission from the Mailbox Transport Submission service to the Transport service failed. |
|
SUPPRESSED |
The message transmission was suppressed. |
|
THROTTLE |
The message was throttled. |
|
TRANSFER |
Recipients were moved to a forked message because of content conversion, message recipient limits, or agents. Sources include ROUTING or QUEUE. |
Source values in the message tracking log
The values in the source field in the message tracking log indicate the transport component that's responsible for the message tracking event. The following table describes the values of the source field.
|
Source value |
Description |
|
ADMIN |
The event source was human intervention. For example, an administrator used Queue Viewer to delete a message, or submitted message files using the Replay directory. |
|
AGENT |
The event source was a transport agent. |
|
APPROVAL |
The event source was the approval framework that's used with moderated recipients. For more information, see Moderated Transport. |
|
BOOTLOADER |
The event source was unprocessed messages that exist on the server at boot time. This is related to the LOAD event type. |
|
DNS |
The event source was DNS. |
|
DSN |
The event source was a delivery status notification (also known as a DSN, bounce message, non-delivery report, or NDR). |
|
GATEWAY |
The event source was a Foreign connector. For more information, see Foreign Connectors. |
|
MAILBOXRULE |
The event source was an Inbox rule. For more information, see Inbox rules. |
|
MEETINGMESSAGEPROCESSOR |
The event source was the meeting message processor, which updates calendars based on meeting updates. |
|
ORAR |
The event source was an Originator Requested Alternate Recipient (ORAR). You can enable or disable support for ORAR on Receive connectors using the OrarEnabled parameter on the New-ReceiveConnectoror Set-ReceiveConnector cmdlets. |
|
PICKUP |
The event source was the Pickup directory. For more information, see Pickup Directory and Replay Directory. |
|
POISONMESSAGE |
The event source was the poison message identifier. For more information about poison messages and the poison message queue, see Queues and messages in queues |
|
PUBLICFOLDER |
The event source was a mail-enabled public folder. |
|
QUEUE |
The event source was a queue. |
|
REDUNDANCY |
The event source was Shadow Redundancy. For more information, see Shadow redundancy in Exchange Server. |
|
ROUTING |
The event source was the routing resolution component of the categorizer in the Transport service. |
|
SAFETYNET |
The event source was Safety Net. For more information, see Safety Net in Exchange Server. |
|
SMTP |
The message was submitted by the SMTP send or SMTP receive component of the transport service. |
|
STOREDRIVER |
The event source was a MAPI submission from a mailbox on the local server. |