Those are all NDR messages.
Do you know if any of the email addresses shown are legit?
Have you looked at your queues to see if you have large number of messages listed?
This is one of two things.
1. DNS problems.
2. Spam.
If the emails are not ones that you normally would expect to go through your server and you have significant amounts of messages in the queues then spam attack is the likely cause.
Take a look at my web site for information on identifying and cleaning up after a spam attack. http://www.amset.info/exch
If your queues are clear or have very small numbers of messages then it could be DNS.
Verify that you have internal DNS servers listed in the DNS configuration on the Exchange server - they should be pointed at the domain controllers only.
You may then need to configure forwarders on your DNS Server configuration on the domain controllers to use your ISPs DNS servers.
Simon.
Main Topics
Browse All Topics





by: luyanPosted on 2005-08-29 at 13:50:20ID: 14779178
The exchange 2003 is on windows 2003 server and do not have sp1. There is a GFI installed on this server. om (Message-ID <WIGGUM66pCYBmAtPbN0000001 00@wiggum. rtviz.com> ).
06@wiggum. rtviz.com> ).
pany.com (Message-ID <WIGGUM3cqnrcstUBBPv000001 0a@wiggum. rtviz.com> ).
(Message-ID <WIGGUM8graBgPO3gMi4000000 fa@wiggum. rtviz.com> ).
Here are some error message:
3008:
A non-delivery report with a status code of 5.0.0 was generated for recipient rfc822;a.koreisha@lucent.c
Cause: This indicates a permanent failure. Possible causes : 1)No route is defined for a given address space. For example, an SMTP connector is configured, but this recipient address does not match the address spaces for which it routes mail. 2)Domain Name Server (DNS) returned an authoritative host not found for the domain. 3)The routing group does not have a connector defined û mail from one server in the routing group has no way to get to another routing group.
Solution: Verify that this error is not caused by a DNS lookup problem, and then check the address spaces configured on your STMP connectors. If you are delivering Internet mail through an SMTP connector, consider adding an address space of type SMTP with value ô*ö (an asterisk) to one of the SMTP connectors to make routing possible. Verify all routing groups are connected to each other through a routing group connector or another connector.
3015:
A non-delivery report with a status code of 5.3.0 was generated for recipient rfc822;kerrie@flash.net (Message-ID <WIGGUMrgN9zp2ZbVGGw000001
Causes: Exchange mistakenly attempted mail delivery to an incorrect MTA route.
3018:
A non-delivery report with a status code of 5.4.0 was generated for recipient rfc822;375_mamacint@jtlcom
Causes: This message indicates a DNS problem or an IP address configuration problem
Solution: Check the DNS using nslookup or dnsq. Verify the IP address is in IPv4 literal format.
3030:
A non-delivery report with a status code of 5.1.8 was generated for recipient rfc822;agache@cisco.uk.com
I have a lot this kind error messages in event log and have different address. Is this a Virus issue or some one else?
Thanks
Yan