Dear experts,
I am experiencing a strange spam issue with my Exchange 2007 server (with the latest service pack and rollups) recently.
My config is:
Exchange 2007 SP1 with latest rollup (x64)
Windows Server 2008 x64
TrendMicro ScanMail (for spam and AV filtering)
I have checked that I am NOT an open relay by telneting to exchange port 25.
Also I have set Accepted Domains in Hub Transport and it is limited to my own domains only.
My problem is:
I am getting outgoing spam from my exchange server on the outgoing SMTP connector the frequency is of this problem is about 3 to 4 spam a day that went thru my outgoing SMTP connector.
Based on what I see from the message tracking tool, I can see that the spam will come thru the incoming SMTP first, destined to one of our real email addresses (as well as a bunch of other non-local email addresses in the CC: field) local to our domain, the spam will then get Quarantined by the content filtering using SCL rating of 7 for our exchange server.
However the spam message will somehow get thru to our outgoing SMTP connector and the message get sent to the non-local recipients in the CC: field
Please find below outgoing and incoming SMTP logs and the relevant part of message tracking log, as well as the header of the spam message itself.
Some notes:
For illustration purpose our domain is mydomain.com (public) and mydomain.local (LAN)
Our exchange mail server is called SPOCK
In these logs I have changed the real user name to real_local_user
Our ISPs SMTP smart host I used for outgoing mail is from fluidata.co.uk
The spammers are spoofing hmrc.gov.gov.uk in this case
Here are the logs:
SMTP receive log:
2009-04-29T09:47:38.466Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,0,1
92.168.116
.4:25,123.
18.150.215
:4384,+,,
2009-04-29T09:47:38.466Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,1,1
92.168.116
.4:25,123.
18.150.215
:4384,*,SM
TPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDom
ainSender AcceptRoutingHeaders,Set Session Permissions
2009-04-29T09:47:38.467Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,2,1
92.168.116
.4:25,123.
18.150.215
:4384,>,"2
20 spock.mydomain.local Microsoft ESMTP MAIL Service ready at Wed, 29 Apr 2009 10:47:37 +0100",
2009-04-29T09:47:39.036Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,3,1
92.168.116
.4:25,123.
18.150.215
:4384,<,HE
LO hmrc.gov.uk,
2009-04-29T09:47:39.037Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,4,1
92.168.116
.4:25,123.
18.150.215
:4384,>,25
0 spock.mydomain.local Hello [123.18.150.215],
2009-04-29T09:47:39.608Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,5,1
92.168.116
.4:25,123.
18.150.215
:4384,<,MA
IL FROM: <operator_num_83wgf@hmrc.g
ov.uk>,
2009-04-29T09:47:39.608Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,6,1
92.168.116
.4:25,123.
18.150.215
:4384,*,08
CB96538CAC
4E8C;2009-
04-29T09:4
7:38.466Z;
1,receivin
g message
2009-04-29T09:47:39.608Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,7,1
92.168.116
.4:25,123.
18.150.215
:4384,>,25
0 2.1.0 Sender OK,
2009-04-29T09:47:40.261Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,8,1
92.168.116
.4:25,123.
18.150.215
:4384,<,RC
PT TO: <real_local_user@mydomain.
com>,
2009-04-29T09:47:40.264Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,9,1
92.168.116
.4:25,123.
18.150.215
:4384,>,25
0 2.1.5 Recipient OK,
2009-04-29T09:47:40.812Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,10,
192.168.11
6.4:25,123
.18.150.21
5:4384,<,D
ATA,
2009-04-29T09:47:40.813Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,11,
192.168.11
6.4:25,123
.18.150.21
5:4384,>,3
54 Start mail input; end with <CRLF>.<CRLF>,
2009-04-29T09:47:42.130Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,12,
192.168.11
6.4:25,123
.18.150.21
5:4384,>,2
50 2.6.0 <000801c9c989$38c6e552$020
1a8c0@c-ff
c4b14a8d7f
4> Queued mail for delivery,
2009-04-29T09:47:42.691Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,13,
192.168.11
6.4:25,123
.18.150.21
5:4384,<,Q
UIT,
2009-04-29T09:47:42.691Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,14,
192.168.11
6.4:25,123
.18.150.21
5:4384,>,2
21 2.0.0 Service closing transmission channel,
2009-04-29T09:47:42.692Z,S
POCK\Defau
lt SPOCK,08CB96538CAC4E8C,15,
192.168.11
6.4:25,123
.18.150.21
5:4384,-,,
Local
SMTP send log:
2009-04-29T09:47:42.269Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,0,,89.105
.96.56:25,
*,,attempt
ing to connect
2009-04-29T09:47:42.277Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,1,192.168
.116.4:203
7,89.105.9
6.56:25,+,
,
2009-04-29T09:47:42.295Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,2,192.168
.116.4:203
7,89.105.9
6.56:25,<,
"220 smtp2.fluidata.co.uk ESMTP Sendmail 8.13.8/8.13.8; Wed, 29 Apr 2009 10:49:43 +0100",
2009-04-29T09:47:42.295Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,3,192.168
.116.4:203
7,89.105.9
6.56:25,>,
EHLO spock.mydomain.com,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,4,192.168
.116.4:203
7,89.105.9
6.56:25,<,
"250-smtp2
.fluidata.
co.uk Hello mydomain.com.fluidata.co.u
k [mydomain.com] (may be forged), pleased to meet you",
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,5,192.168
.116.4:203
7,89.105.9
6.56:25,<,
250-ENHANC
EDSTATUSCO
DES,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,6,192.168
.116.4:203
7,89.105.9
6.56:25,<,
250-PIPELI
NING,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,7,192.168
.116.4:203
7,89.105.9
6.56:25,<,
250-8BITMI
ME,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,8,192.168
.116.4:203
7,89.105.9
6.56:25,<,
250-SIZE,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,9,192.168
.116.4:203
7,89.105.9
6.56:25,<,
250-DSN,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,10,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250-ETRN,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,11,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250-DELIV
ERBY,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,12,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 HELP,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,13,192.16
8.116.4:20
37,89.105.
96.56:25,*
,419,sendi
ng message
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,14,192.16
8.116.4:20
37,89.105.
96.56:25,>
,MAIL FROM:<operator_num_83wgf@h
mrc.gov.uk
> SIZE=11988,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,15,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@cnsfar
nell.com>,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,16,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@city.a
c.uk>,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,17,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@excite
.co.uk>,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,18,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@elsevi
er.com>,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,19,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@bywate
rs.co.uk>,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,20,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@bradfo
rdcollege.
ac.uk>,
2009-04-29T09:47:42.305Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,21,192.16
8.116.4:20
37,89.105.
96.56:25,>
,RCPT TO:<real_local_user@breath
e.com>,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,22,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.0 <operator_num_83wgf@hmrc.g
ov.uk>... Sender ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,23,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@cnsfarnel
l.com>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,24,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@city.ac.u
k>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,25,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@excite.co
.uk>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,26,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@elsevier.
com>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,27,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@bywaters.
co.uk>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,28,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@bradfordc
ollege.ac.
uk>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,29,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.1.5 <real_local_user@breathe.c
om>... Recipient ok,
2009-04-29T09:47:42.599Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,30,192.16
8.116.4:20
37,89.105.
96.56:25,>
,DATA,
2009-04-29T09:47:42.607Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,31,192.16
8.116.4:20
37,89.105.
96.56:25,<
,"354 Enter mail, end with ""."" on a line by itself",
2009-04-29T09:47:43.448Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,32,192.16
8.116.4:20
37,89.105.
96.56:25,<
,250 2.0.0 n3T9nhiG006511 Message accepted for delivery,
2009-04-29T09:47:43.448Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,33,192.16
8.116.4:20
37,89.105.
96.56:25,>
,QUIT,
2009-04-29T09:47:43.455Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,34,192.16
8.116.4:20
37,89.105.
96.56:25,<
,221 2.0.0 smtp2.fluidata.co.uk closing connection,
2009-04-29T09:47:43.455Z,M
ain SMTP Send Connector,08CB96538CAC4E8E
,35,192.16
8.116.4:20
37,89.105.
96.56:25,-
,,Local
message tracking log:
2009-04-29T09:47:42.130Z,1
23.18.150.
215,,192.1
68.116.4,s
pock,08CB9
6538CAC4E8
C;2009-04-
29T09:47:3
8.466Z;0,S
POCK\Defau
lt SPOCK,SMTP,RECEIVE,419,<00
0801c9c989
$38c6e552$
0201a8c0@c
-ffc4b14a8
d7f4>,,,74
08,1,,,HM Revenue and Customs Notification Tax refund (Internal Revenue Service),operator_num_83wg
f@hmrc.gov
.uk,operat
or_num_83w
gf@hmrc.go
v.uk,00A:
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@mydom
ain.com,,0
,1,,,,,ope
rator_num_
83wgf@hmrc
.gov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@bradf
ordcollege
.ac.uk,,0,
1,,,,,oper
ator_num_8
3wgf@hmrc.
gov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@breat
he.com,,0,
1,,,,,oper
ator_num_8
3wgf@hmrc.
gov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@bywat
ers.co.uk,
,0,1,,,,,o
perator_nu
m_83wgf@hm
rc.gov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@city.
ac.uk,,0,1
,,,,,opera
tor_num_83
wgf@hmrc.g
ov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@cnsfa
rnell.com,
,0,1,,,,,o
perator_nu
m_83wgf@hm
rc.gov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@elsev
ier.com,,0
,1,,,,,ope
rator_num_
83wgf@hmrc
.gov.uk,
2009-04-29T09:47:42.192Z,,
spock,,,,,
AGENT,RECE
IVE,419,,r
eal_local_
user@excit
e.co.uk,,0
,1,,,,,ope
rator_num_
83wgf@hmrc
.gov.uk,
2009-04-29T09:47:42.268Z,,
,,spock,Qu
arantine,,
DSN,DSN,42
0,<44a7df5
a-7fdb-4d1
b-a71d-560
aa8754617>
,email_adm
in@mydomai
n.com,,180
10,1,,,Und
eliverable
: ,postmaster@mydomain.com,<
>,
2009-04-29T09:47:42.322Z,,
spock,,spo
ck,,,STORE
DRIVER,DEL
IVER,419,,
real_local
_user@mydo
main.com,,
11988,1,,,
,,operator
_num_83wgf
@hmrc.gov.
uk,2009-04
-29T09:47:
40.813Z
2009-04-29T09:47:42.985Z,,
spock,,spo
ck,,,STORE
DRIVER,DEL
IVER,420,<
44a7df5a-7
fdb-4d1b-a
71d-560aa8
754617>,em
ail_admin@
mydomain.c
om,,18491,
1,,,Undeli
verable: ,postmaster@mydomain.com,A
dministrat
or@mydomai
n.com,
2009-04-29T09:47:43.448Z,1
92.168.116
.4,spock,8
9.105.96.5
6,smtp2.fl
uidata.co.
uk,08CB965
38CAC4E8E,
Main SMTP Send Connector,SMTP,SEND,419,<0
00801c9c98
9$38c6e552
$0201a8c0@
c-ffc4b14a
8d7f4>,rea
l_local_us
er@cnsfarn
ell.com;re
al_local_u
ser@city.a
c.uk;real_
local_user
@excite.co
.uk;real_l
ocal_user@
elsevier.c
om;real_lo
cal_user@b
ywaters.co
.uk;real_l
ocal_user@
bradfordco
llege.ac.u
k;real_loc
al_user@br
eathe.com,
250 2.1.5 <real_local_user@cnsfarnel
l.com>... Recipient ok;250 2.1.5 <real_local_user@city.ac.u
k>... Recipient ok;250 2.1.5 <real_local_user@excite.co
.uk>... Recipient ok;250 2.1.5 <real_local_user@elsevier.
com>... Recipient ok;250 2.1.5 <real_local_user@bywaters.
co.uk>... Recipient ok;250 2.1.5 <real_local_user@bradfordc
ollege.ac.
uk>... Recipient ok;250 2.1.5 <real_local_user@breathe.c
om>... Recipient ok,11984,7,,;;;;;;,HM Revenue and Customs Notification Tax refund (Internal Revenue Service),operator_num_83wg
f@hmrc.gov
.uk,operat
or_num_83w
gf@hmrc.go
v.uk,2009-
04-29T09:4
7:40.813Z
the spam message header:
Delivery of this message to the following recipients or distribution lists is quarantined:
real_local_user@mydomain.c
om
Subject:
--------------------------
----------
----------
----------
----------
----------
----
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: mydomain.local
real_local_user@mydomain.c
om
#550 5.2.1 Content Filter agent quarantined this message ##
Original message headers:
thread-index: AcnIr4pOQbUab6mNS6mROwyg1O
sA5Q==
Received: from hmrc.gov.uk (123.18.150.215) by spock.mydomain.local (192.168.116.4) with Microsoft SMTP Server id 8.1.358.0; Wed, 29 Apr 2009 10:47:40 +0100
Message-ID: <000801c9c989$38c6e552$020
1a8c0@c-ff
c4b14a8d7f
4>
From: "HMRC Tax Refunds On-line" <operator_num_83wgf@hmrc.g
ov.uk>
To: <real_local_user@mydomain.
com>
BCC: <real_local_user@bradfordc
ollege.ac.
uk>,
<real_local_user@breathe.c
om>,
<real_local_user@bywaters.
co.uk>,
<real_local_user@city.ac.u
k>,
<real_local_user@cnsfarnel
l.com>,
<real_local_user@elsevier.
com>,
<real_local_user@excite.co
.uk>
Subject: HM Revenue and Customs Notification Tax refund (Internal Revenue Service)
Content-Transfer-Encoding:
7bit
Date: Thu, 30 Apr 2009 04:45:55 -0700
MIME-Version: 1.0
Content-Type: multipart/related;
boundary="----=_NextPart_0
00_0004_01
C9C94E.8C6
59770";
type="multipart/alternativ
e"
X-Priority: 3
X-MSMail-Priority: Normal
Content-Class: urn:content-classes:messag
e
Importance: normal
Priority: normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18049
Return-Path: <operator_num_83wgf@hmrc.g
ov.uk>
Received-SPF: None (spock.mydomain.local: operator_num_83wgf@hmrc.go
v.uk does not designate permitted sender hosts)
X-TM-AS-Product-Ver: SMEX-8.0.0.4125-5.600.1016
-16610.003
X-TM-AS-Result: Yes-64.271900-4.000000-31
X-TM-AS-User-Approved-Send
er: No
X-TM-AS-User-Blocked-Sende
r: No