One of my users came in this morning and had 600 non-delivery reports in her Inbox. I think this has been referred to as the "Reverse NDR attack". This is NOT the first user on my network to have this problem. It seems this spammer I picking on a different user every week. The problem, in case you don't already know, is this.......
1.) Spammer sends an email to "randomcrap@somedomain.com
" and for the from puts "user@mydomain.com"
2.) The server at "somedomain.com" does not have a user name "randomcrap".......so it sends a NDR to "user@mydomain.com".......
not knowing the email address is spoofed.
3.) user's inbox fills up with these NDRs and the admin at "somedomain.com" is getting mad because "mydomain.com" is spamming him.
I'm pretty sure there is no way to stop the spammer from sending this junk in the first place. But at the very least, could someone tell me how to stop my user's inboxs from filling up with this crap??
Thanks for your help and insights.
Kindest regards,
Bryce
Start Free Trial