Solved

exchange 2003 Inbound Recipient Filtering at smtp level doesn't work

Posted on 2004-08-11
5
721 Views
Last Modified: 2011-09-20
I wan't to use the filter recipients rules at smtp level as defined in Exchange 2003.

My intranet domain is SOLID-DYNAMICS.OFFICE

I receive emails for domain SOLID-DYNAMICS.COM and SOLID-DYNAMICS.FR

I've configured my server properly (it's seems) (I've just upgrade my serveur in EXC2003, we have a EXC2000 Server before)

I've read and applyed the document downloaded at : http://download.microsoft.com/download/9/4/d/94df821b-45fe-48fa-a866-dec23513d700/WN2k3.exe named "What's new in excahnge 2003" chapter : "Inbound Recipient Filtering page 166".

When I telnet my server, all recipients are accepted even if they are not in AD.

I've also added directly some users in the list box, but nothing to do : all recipients are allowed...

Need help, my server receive at leat 90% of junk email on wrong adress and send NDR...

Thanks

0
Comment
Question by:FredTachet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 17

Expert Comment

by:Microtech
ID: 11771653
By default Exchange won't process the recipient until after it has received the message as long as the domain part is valid per the recipient policy(s).

If you enable recipient filtering and check "Filter recipients who are not in the directory" then you will get 550's for invalid local recipients.
This will eliminate the need for your system to generate NDR's for messages that are sent to non-existent users. Which in the case of spammers, the sender is either an invalid destination (NDR gets stuck in retry until the message times out) or an invalid user. Both of these case caues the NDR to be dumped in the badmail directory, thus making it difficult to keep track of real badmail issues.

On the other side of the coin, it makes it easier for a remote party to perform a directory harvest attack. Please note the word easier, as some people are under the false assumption that DHA's can't happen if you don't have recipient filtering. DHA's can happen without recipient filtering by processing NDR's and removing the recipients from the spamlist.
0
 

Author Comment

by:FredTachet
ID: 11772015
>> If you enable recipient filtering and check "Filter recipients who are not in the directory" then you will get 550's for invalid local recipients.
That's what I want. Never mind for DHA now...
The problem is that we have a lot of customers that are not well protected against viruses, and that's why we receice a lot of junk or viruses emails.

Our spam and virus scan engine clean every of them, but this morning we have recevied 11 legitimate emails, 83 junk emails,  and 642 unknown user mail...

The strange thing is that I've already done it on an other exchange 2003 server as it's explain on the word documentation from MS and it's working fine, but I can figure out why it doesn't work for this server. The only difference I can see is That this one is an upgrade from EXC2000 and the other is a fresh install.

Thanks


0
 
LVL 17

Accepted Solution

by:
Microtech earned 125 total points
ID: 11773230
"Recipient filter rules apply only to anonymous connections. Authenticated users and Exchange servers bypass these validations". ref the doc you put a link to.
make sure no one is relaying

also look at this doc see if it helps http://support.microsoft.com/default.aspx?scid=KB;EN-US;823866


0
 

Author Comment

by:FredTachet
ID: 11773623
A friend of mine tell me to try to repair my installation, because sometimes there is problem with upgrade...

That's what I've done, and all is working fine now...

The repair has removed a connector used to fight relay in EXC2000, it's perhaps this connector that cause the problem.

Anyway thank for your time Microtech.

Topic is closed.
0
 
LVL 17

Expert Comment

by:Microtech
ID: 11773912
Glad I could help a bit... if you feel I am deserving of the points the accept one of my comments

or if you wish to close then post a please close this question link in community support http://www.experts-exchange.com/Community_Support/
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question