Undeliverable spam mail from the System Administrator clogging inbox that was never sent in the first place

A collegue of mine is receiving hundreds of emails from the system administrator in his inbox with the subject: "Undeliverable" at the begining.

The problem is that the emails are caused by sending mail to a non-existent email address. However he is not sending any emails to any of the addresses. We think there is a virus on an external computer that has his email address and is sending out hundreds of email to 'made-up' email addresses. When these email addresses get rejected then he is receiving all the Undeliverable messages in his inbox.

Is there anyway to either
1. prevent the mail at our end
2. stop the system administrator emails
3. automatically move the system administrator emails to a seperate folder.
4. any other suggestions....

I have tried setting up a rule in Microsoft office but this will not work as it says it's an internal email.
We are running Microsoft Exchange.

Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Which version of Exchange?

This sounds like an NDR attack.
First thing I would do is disable system administrator messages on the SMTP virtual server.

On the Messages tab, clear the box "Send copy of Non-Delivery Report to:"
You may want to disable NDRs in ESM as well.

Have you looked at the queues? There may be a large number of messages waiting which would also indicate that they are being sent through your server.

There are some other options, but further diagnostics is dependant on the Exchange version and what is in the queues.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.