Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Strange messages in out queue

Posted on 2004-04-22
5
219 Views
Last Modified: 2012-08-13
I have an Exchange Server 5.5 that gathers about 100 or so strange messages in the Outbound Awaiting Delivery queue every day in a slow trickle.

They look like spam or virus related things - they will have no originator and the destination is always some sort of loopy bs address like aaa5.8m.com, groogle.com, or the like.  They fail with a [network error during host resolution] message and just build up out there in the queue.  I have been purging them manually, but am concerned about their source.

We are not open relaying - everything requires authentication and I've been through the process of covering relay holes.  We WERE at one time open relaying and were being used for spam for about a month before I found it, several years ago.  I am also pretty confident that no one is purposefully using a mass mailer inside the building.  We are well antivirused, so I don't think someone is hosting a trojan innocently.

Can anyone help me identify the source of these messages and determine how to fix the root problem behind it?
0
Comment
Question by:breid7718
  • 2
5 Comments
 
LVL 15

Expert Comment

by:getzjd
ID: 10890467
These are probably NDR's that spammers are using to send email now.  Turn off NDR's or you will have to use a 3rd party software solution.  Only exchange 2003 has the ability to filter out these emails automatically.  http://www.cmsconnect.com/  or I believe GFI mail essentials will help out also.

Read this to understand a reverse NDR attack http://www.cmsconnect.com/Praetor/RNDR/prRNDR.htm
0
 
LVL 1

Author Comment

by:breid7718
ID: 10891017
I can find Administratior notifications for NDRs (and have them turned off) on the IMS property page, but I don't see an option to actually turn off NDRs.  Where can I find that option?
0
 
LVL 15

Accepted Solution

by:
getzjd earned 500 total points
ID: 10891237
I was slightly off in saying to disable ndr's in exchange 5.5.  Sorry about that.. I have all my clients on 2k and 2k3 now so I didnt even think about it.

 This can only be done in 2000 and up.   Check out this thread http://www.tek-tips.com/gpviewthread.cfm/qid/655444/pid/10/lev2/3/lev3/15

There hare many suggestions in there.  Some of the filtering software can be found fairly cheap as well.  You may want to check those out.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
Find out what you should include to make the best professional email signature for your organization.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question