Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Block invalid NDR's

Posted on 2004-09-01
7
Medium Priority
?
1,664 Views
Last Modified: 2007-12-19
Does anyone know of a way to block invalid NDR's with Exchange 2000 - ie NDR's to emails not actually sent by a user within our organisation (typically when their email address has been spoofed by a spammer)? I don't want to block all inbound DSN's or even valid NDR's. I just want to block NDR's from external addresses in reply to emails that were never actually sent from within our organisation. I suspect that their may be a way to do this by doing some sort of reverse lookup on the originating domain in the NDR - to show that that the email that the NDR is a reply to did not genuinely originate from our domain? Is this possible?

Please help! One user in particular (who has obviously had his address spoofed by a load of spammers) is getting overwhelmed with NDR's for email he has not sent. What’s more they are forwarding all the erroneous NDR's to my boss :-(
0
Comment
Question by:samcadby
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
7 Comments
 
LVL 17

Expert Comment

by:Microtech
ID: 11950544
Hi samcadby,

there is only the all or nothing approach here, unless you go with a spam blocker which can send out its own ndr's.

in exchange server the way to stop ndrs is to go to esm then to global settings> internet message format> right click on default and select properties. then you will see a tick box under the advanced tab for ndr's.

Hope This helps
0
 
LVL 17

Expert Comment

by:Microtech
ID: 11950549
gfi mail essentials will achieve what you are looking to do, there are obviously other 3rd party tools http://www.gfi.com/mes/
0
 

Author Comment

by:samcadby
ID: 11950738
Hmmm,

gfi can reverse lookup to block mail from domains where the MX does not match the IP (good) but the NDR's we're getting are from valid domains but in reply to emails from invalid domains (as the original sender is spoofed). Does anyone know if GFI can traverse all the headers and reject if the domain is invalid in any of the headers, not just the top one?
I'm also slightly nervous about blocking based solely on bad domains - some people may be legitimately masquerading a domain. A better solution would be a way of correlated NDR's to sent mails and rejecting the NDR's where there is no correlating outgoing mail from our domain...

We live in hope! Any more ideas anyone?
0
 
LVL 17

Accepted Solution

by:
Microtech earned 1000 total points
ID: 11950804
you may also want to see this link, BNettles73 has given a good explaination of spoof e-mails and what you can do about them.
http://www.experts-exchange.com/Networking/Email_Groupware/Exchange_Server/Q_21108443.html

I believe that GFI does a check for invalid headers, not sure though.
0

Featured Post

Tech or Treat!

Submit an article about your scariest tech experience—and the solution—and you’ll be automatically entered to win one of 4 fantastic tech gadgets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The main intent of this article is to make you aware of ‘Exchange fail to mount’ error, its effects, causes, and solution.
Here in this article, you will get a step by step guidance on how to restore an Exchange database to a recovery database. Get a brief on Recovery Database and how it can be used to restore Exchange database in this section!
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
This video discusses moving either the default database or any database to a new volume.
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question