Exchange 2007 Dynamic Dist Group Bug
After spending about 7 hours on query-based distribution lists in Exchange 2007 and racking my brain I found the answer… It’s a known bug.
After creating a group with the -recipientContainer filter pointing to a specific OU the preview in Exchange 2007 MMC would still result in the preview showing ALL mailboxes regardless of their OU. Which led me to believe my query was wrong but in fact if you send a test email (scary) to the OU then in Exchange in message tracking it shows that the recipients are in fact limited to the OU you select in the -recipientContainer.
Reference: http://www.zerohoursleep.com/2010/03/bug-revealed-in-dynamic-distribution-groups-on-exchange-2007/