Solved

Strange messages in out queue

Posted on 2004-04-22
5
215 Views
Last Modified: 2012-08-13
I have an Exchange Server 5.5 that gathers about 100 or so strange messages in the Outbound Awaiting Delivery queue every day in a slow trickle.

They look like spam or virus related things - they will have no originator and the destination is always some sort of loopy bs address like aaa5.8m.com, groogle.com, or the like.  They fail with a [network error during host resolution] message and just build up out there in the queue.  I have been purging them manually, but am concerned about their source.

We are not open relaying - everything requires authentication and I've been through the process of covering relay holes.  We WERE at one time open relaying and were being used for spam for about a month before I found it, several years ago.  I am also pretty confident that no one is purposefully using a mass mailer inside the building.  We are well antivirused, so I don't think someone is hosting a trojan innocently.

Can anyone help me identify the source of these messages and determine how to fix the root problem behind it?
0
Comment
Question by:breid7718
  • 2
5 Comments
 
LVL 15

Expert Comment

by:getzjd
ID: 10890467
These are probably NDR's that spammers are using to send email now.  Turn off NDR's or you will have to use a 3rd party software solution.  Only exchange 2003 has the ability to filter out these emails automatically.  http://www.cmsconnect.com/  or I believe GFI mail essentials will help out also.

Read this to understand a reverse NDR attack http://www.cmsconnect.com/Praetor/RNDR/prRNDR.htm
0
 
LVL 1

Author Comment

by:breid7718
ID: 10891017
I can find Administratior notifications for NDRs (and have them turned off) on the IMS property page, but I don't see an option to actually turn off NDRs.  Where can I find that option?
0
 
LVL 15

Accepted Solution

by:
getzjd earned 500 total points
ID: 10891237
I was slightly off in saying to disable ndr's in exchange 5.5.  Sorry about that.. I have all my clients on 2k and 2k3 now so I didnt even think about it.

 This can only be done in 2000 and up.   Check out this thread http://www.tek-tips.com/gpviewthread.cfm/qid/655444/pid/10/lev2/3/lev3/15

There hare many suggestions in there.  Some of the filtering software can be found fairly cheap as well.  You may want to check those out.
0

Featured Post

Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video discusses moving either the default database or any database to a new volume.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now