Hi Experts
We have recently been the victim of an NDR attack on our exchange server (2003) on server (2003) and followed all the instructions found on this site to rectify the problem including recipient filtering, turning of NDR's, tarpitting and cleaning out the bad mail and email queues. All seems to be working fine in so far as mail is being delivered and received as I would expect. My question is however I am still receiving error messages in the application event log saying that the server is unable to relay for (fictitious email address). While it would appear that my server is no longer replying, storing or queueing these emails I am concerned that the messages may still be being sent to our server consuming our available bandwidth. Is this likely to be the case, if so how can I stop them getting this far or am I barking up the wrong tree altogether.
Any help would be appreciated.
Start Free Trial