?
Solved

SPAM Recipient question

Posted on 2004-11-25
5
Medium Priority
?
449 Views
Last Modified: 2006-11-17
We are looking into some spam that was received last night and are curious as to how it got around our network.

The email is a plain text message with what I assume is a fake From: address, the intersting part about this spam though is the recipient, Mail-User@ourdomain.com.  We don't have a mailbox or DL using this account but the mail was still received by about 50 users that we know of.

I've tried to sending a message to Mail-User@ourdomain.com but it comes back as not valid. Can anyone explain how this got to our users mailboxes?

We are using Exchange 5.5 SP4

thanx
0
Comment
Question by:burtco013
  • 2
  • 2
5 Comments
 
LVL 6

Expert Comment

by:v_alber
ID: 12675988
Message sample:
===========

To: Mail-User@ourdomain.com
CC:
BCC: all your domain users

Every-one will see Mail-User@ourdomain.com, but the message could be sent to all other people
0
 
LVL 104

Expert Comment

by:Sembee
ID: 12675990
The user addresses were probably in the BCC. A false user was used to get round some of the anti-spam tools which reject email messages with no recipients.

Simon.
0
 

Author Comment

by:burtco013
ID: 12676015
is there a way to find out who wa on the BCC list?
0
 
LVL 6

Accepted Solution

by:
v_alber earned 400 total points
ID: 12676051
Yes, if you have message tracking enabled, you can serach for specific message and where it landed
0
 

Author Comment

by:burtco013
ID: 12676324
Thanx v_alber

we were able to track the message and found the BCC was to a DL on our server
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you have come across a situation where you need to find some EDB mailbox recovery techniques, then here you will find the same. In this article, we will take you through three techniques using which you will be able to perform EDB recovery. You …
Steps to fix error: “Couldn’t mount the database that you specified. Specified database: HU-DB; Error code: An Active Manager operation fail”
This video discusses moving either the default database or any database to a new volume.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Suggested Courses
Course of the Month13 days, 18 hours left to enroll

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question