Quite possibly these are NDR's from spammers mails; they will not be sent by your mail system necessarily, but they are using a live mail address registered to you, and that is why you are getting the NDRs - if the recipient's mail system uses reverse lookup, their mail server will try and lookup your mail server, and when the IP doesn't resolve to your mail server, an NDR is returned to the address that it was supposedly sent from ie. your user
Another reason to hate spammers..
hope this helps you
Main Topics
Browse All Topics





by: Mr-MadcowzPosted on 2008-11-26 at 03:24:00ID: 23041073
Firstly I would enable message tracking so that you can see what is going on in a bit more detail:
tutorials/ The_Exchan ge_Message _Tracking_ Center_or_ How_to_Sav e_Your_A_i n_a_Pinch. html
ngeservern ame.log\
ange/filte r-unknown. asp
/pages/dns report.php
om/en-us/l ibrary/bb1 23843.aspx echnet/sec urity/prod tech/ excha ngeserver/ excrelay.m spx
Enabling the Exchange Message Tracking Center
http://www.msexchange.org/
Then either use the Message tracking center under Tools in ESM or view the actual raw logs in \\Exchangeservername\Excha
Search on the recipient address
It all sounds as though the emails are spoofing one of your users. This happens all the time and I wouldn't worry about it. It goes in waves, some months are worse than others.
Run through these actions to double check your server is configured correctly:
You could set it to not accept messages for non existant users:
http://www.amset.info/exch
and run through these:
a) Check the mail smtp queues in Exchange System Manager to see if there is unusual activity.
b) Do a DNS test at http://member.dnsstuff.com
c) See if you are blacklisted at http://www.robtex.com/
d) In case you need to secure your server:
http://technet.microsoft.c
http://www.microsoft.com/t