• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 605
  • Last Modified:

Sybari e-mail address doesn't seem to work (Exchange message trace attached)

Howdy;

I use Sybari Antigen with Advanced Spam Manager here at my office, and I am having issues with too much spam getting through.   I read the ASM white paper which indicates there is an e-mail to send false negatives to, so that Sybari can create new signatures for their SpamCure engine.   Unfortunately, everything I have sent to them has generated an NDR (from our own exchange box) a couple of days later.

The e-mail as advertised is: Spam.mail-filters@research.sybari.com

Is this correct?   I did a message trace on our Exchange 2003 server, and I've copied the trace results here (Time Stamps removed for simplicity, can be added on request):
SMTP Store Driver: Message submitted from Store
SMTP: Message Submitted to Advanced Queuing
SMTP: Started Message Submission to Advanced Queue
SMTP: Message Submitted to Categorizer
SMTP: Message Categorized and Queued for Routing
SMTP: Message Routed and Queued for Remote Delivery
SMTP: Started Outbound Transfer of Message
Message Transferred to  through SMTP
SMTP: Started Outbound Transfer of Message
Message Transferred to  through SMTP
SMTP: Non-Delivered Report (NDR) Generated

Any ideas on what's going wrong here?

Thanks for the help.

Dice.
0
Diceman_01
Asked:
Diceman_01
  • 3
  • 3
1 Solution
 
tymesCommented:
We need SMTP log messages.  Turn on SMTP logging and give us those logs.

Or the error message in the message your get back... it should say what when wrong since it did go as far as SMTP.
Look for lines like .... <<< 550 5.7.1 blah blah blah reason.
0
 
Diceman_01Author Commented:
Thanks for the reply.

Here is the text from one of the NDRs:

=====BEGIN NDR=====
Your message did not reach some or all of the intended recipients.

      Subject:      FW: The Ultimate Online Pharmaceutical
      Sent:      3/17/2006 3:44 PM

The following recipient(s) could not be reached:

      'Spam' on 3/19/2006 3:46 PM
            Could not deliver the message in the time limit specified.  Please retry or contact your administrator.
            <yk-exch-2.corp.wcb.nt.ca #4.4.7>
=====END NDR=====

Perhaps obviously, the recipient 'Spam' is my outlook contact for spam.mail-filters@research.sybari.com.

I did a search on SMTP 4.4.7 and it mentioned the badmail directory, so I checked the "Mailroot\vsi 1\BadMail" directory, but it was empty.

In the meantime, I've turned on SMTP tracking, (as per these directions: http://www.msexchange.org/tutorials/Logging_the_SMTP_Service.html) and have re-sent the message.   Looking at the SMTP logs, I see that the time stamps start at 15:53 and continue from there.   From this, I can only assume that the timestamps are all in GMT - is this correct?   For the time being, I will assume this is correct and proceed accordingly.  

By checking Exchange 2003 message tracking, I was able to see that my message was submitted to the SMTP service at 9:25am (GMT-0700).  In the SMTP logs, I isolated the events that occured from 16:24:00 GMT to 16:26:59 GMT and read the lines from the log, but none of the messages seemed to be my outbound message.   Moreover, _every_ message appeared to be an inbound message.   This appears to be true for the entire log.   As I scroll through the log, everything appears to be documenting connections established by external servers.   Am I missing something here - maybe I've turned on the wrong tracking?

At any rate, as requested, here are the logs.   To minimize extraneous information, I've only included events that occured from 16:24:00 GMT to 16:26:59 GMT, but can expand this on request.

=====BEGIN SMTP LOG=====
2006-03-21 16:24:09 216.126.110.222 gwichin.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +gwichin.nt.ca 250 0 319 18 0 SMTP - - - -
2006-03-21 16:24:09 216.126.110.222 gwichin.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<TWilliams@gwichin.nt.ca> 250 0 48 35 0 SMTP - - - -
2006-03-21 16:24:09 216.126.110.222 gwichin.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<davegru@wcb.nt.ca> 250 0 30 27 0 SMTP - - - -
2006-03-21 16:24:09 216.126.110.222 gwichin.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 BDAT - +<E5035C2E79F4AF41BB37A88A793EC7B283F76A@chief.Gwichin.local> 250 0 98 2377 172 SMTP - - - -
2006-03-21 16:24:09 216.126.110.222 gwichin.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - gwichin.nt.ca 240 375 73 4 0 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 220+SMTP.technolog.fr 0 0 21 0 1282 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 EHLO - yk-exch-2.corp.wcb.nt.ca 0 0 4 0 1282 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250-ns0.technolog.fr 0 0 20 0 1485 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 MAIL - FROM:<JeanneeJ@wcb.nt.ca>+SIZE=836 0 0 4 0 1485 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+Ok 0 0 6 0 1672 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 RCPT - TO:<hu2ivoa8@cogit.fr> 0 0 4 0 1672 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 450+<hu2ivoa8@cogit.fr>:+Recipient+address+rejected:+User+unknown+in+local+recipient+table 0 0 90 0 1891 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 RSET - - 0 0 4 0 1891 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+Ok 0 0 6 0 2079 SMTP - - - -
2006-03-21 16:24:22 62.23.69.197 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 QUIT - - 0 0 4 0 2094 SMTP - - - -
2006-03-21 16:24:23 62.23.69.197 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 221+Bye 0 0 7 0 2282 SMTP - - - -
2006-03-21 16:24:37 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +igloo1.gov.nt.ca 250 0 318 21 0 SMTP - - - -
2006-03-21 16:24:37 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<Laurie_Moroz@gov.nt.ca> 250 0 47 44 0 SMTP - - - -
2006-03-21 16:24:37 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<donnag@wcb.nt.ca> 250 0 29 26 15 SMTP - - - -
2006-03-21 16:24:37 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 DATA - +<H00001c20d59f6e9.1142958247.arctic42.gov.nt.ca@MHS> 250 0 136 2612 547 SMTP - - - -
2006-03-21 16:24:37 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - igloo1.gov.nt.ca 240 1297 73 4 0 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 220+yk-asavprd-02.mx.northwestel.net+ESMTP+Sendmail+8.12.11/8.12.11;+Tue,+21+Mar+2006+09:25:05+-0700 0 0 100 0 5235 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 EHLO - yk-exch-2.corp.wcb.nt.ca 0 0 4 0 5235 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250-yk-asavprd-02.northwestel.net+Hello+247-1-1.ntnet.nt.ca+[199.247.1.1]+(may+be+forged),+pleased+to+meet+you 0 0 110 0 5235 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 MAIL - FROM:<Jeremyst@wcb.nt.ca>+SIZE=2489 0 0 4 0 5235 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+2.1.0+<Jeremyst@wcb.nt.ca>...+Sender+ok 0 0 43 0 5235 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 RCPT - TO:<adrien@polartech.ca> 0 0 4 0 5235 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+2.1.5+<adrien@polartech.ca>...+Recipient+ok 0 0 47 0 5250 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 DATA - - 0 0 4 0 5250 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 354+Enter+mail,+end+with+"."+on+a+line+by+itself 0 0 48 0 5250 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+2.0.0+k2LGP5mM004221+Message+accepted+for+delivery 0 0 54 0 5344 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 QUIT - - 0 0 4 0 5360 SMTP - - - -
2006-03-21 16:25:20 198.235.201.4 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 221+2.0.0+yk-asavprd-02.northwestel.net+closing+connection 0 0 58 0 5360 SMTP - - - -
2006-03-21 16:25:51 221.188.212.11 - SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - - 240 0 199 4 0 SMTP - - - -
2006-03-21 16:25:55 65.54.174.14 hotmail.com SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +hotmail.com 250 0 316 16 0 SMTP - - - -
2006-03-21 16:25:55 65.54.174.14 hotmail.com SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<lindakcooper@hotmail.com> 250 0 49 36 0 SMTP - - - -
2006-03-21 16:25:55 65.54.174.14 hotmail.com SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<marianad@wcb.nt.ca> 250 0 31 28 0 SMTP - - - -
2006-03-21 16:25:55 65.54.174.14 hotmail.com SMTPSVC1 YK-EXCH-2 192.168.5.23 0 BDAT - +<BAY103-F423257C473EF350869FE4CED80@phx.gbl> 250 0 82 1128 391 SMTP - - - -
2006-03-21 16:25:55 65.54.174.14 hotmail.com SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - hotmail.com 240 703 73 4 0 SMTP - - - -
2006-03-21 16:25:58 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 220+iq-file-2.corp.wcb.nt.ca+Microsoft+ESMTP+MAIL+Service,+Version:+6.0.3790.1830+ready+at++Tue,+21+Mar+2006+11:25:57+-0500+ 0 0 124 0 1203 SMTP - - - -
2006-03-21 16:25:58 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 EHLO - yk-exch-2.corp.wcb.nt.ca 0 0 4 0 1203 SMTP - - - -
2006-03-21 16:25:58 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250-iq-file-2.corp.wcb.nt.ca+Hello+[192.168.5.23] 0 0 49 0 1891 SMTP - - - -
2006-03-21 16:26:00 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 334+GSSAPI+supported 0 0 20 0 2688 SMTP - - - -
2006-03-21 16:26:01 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 334+oYGhMIGeoAMKAQChCwYJKoZIgvcSAQICooGJBIGGYIGDBgkqhkiG9xIBAgICAG90MHKgAwIBBaEDAgEPomYwZKADAgEXol0EW65Mo4ifJjOmkzjr3bJfXFL1Nez4lJjSXuzTZPl/OPvouME3HeSOzZZtXUmnoKORao0kKMvq9Otu0cffzDhMjtzsF3LGBstgImAtPEJn9DdNxmMkBFRV2ugdp5A= 0 0 224 0 3750 SMTP - - - -
2006-03-21 16:26:01 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 235+2.7.0+Authentication+successful. 0 0 36 0 4469 SMTP - - - -
2006-03-21 16:26:01 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 X-LINK2STATE - LAST+CHUNK={0000006a}+MULTI+(5)+({00000051}+DIGEST_QUERY+37fd792e7f78744b9e898f737019301b+95708ee23c2b5a9ea046f284b16c0ac6++)++ 0 0 12 0 4469 SMTP - - - -
2006-03-21 16:26:02 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 200+LAST+CHUNK={00000029}+MULTI+(5)+({00000010}+DONE_RESPONSE++)++ 0 0 66 0 5172 SMTP - - - -
2006-03-21 16:26:02 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 MAIL - FROM:<lindakcooper@hotmail.com>+AUTH=<> 0 0 4 0 5172 SMTP - - - -
2006-03-21 16:26:02 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+2.1.0+lindakcooper@hotmail.com....Sender+OK 0 0 47 0 5891 SMTP - - - -
2006-03-21 16:26:02 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 RCPT - TO:<MarianaD@wcb.nt.ca> 0 0 4 0 5891 SMTP - - - -
2006-03-21 16:26:03 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+2.1.5+MarianaD@wcb.nt.ca+ 0 0 29 0 6578 SMTP - - - -
2006-03-21 16:26:03 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 XEXCH50 - 1076+2 0 0 7 0 6578 SMTP - - - -
2006-03-21 16:26:03 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 354+Send+binary+data 0 0 20 0 7282 SMTP - - - -
2006-03-21 16:26:05 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+XEXCH50+OK 0 0 14 0 8016 SMTP - - - -
2006-03-21 16:26:05 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 BDAT - 1300+LAST 0 0 4 0 8016 SMTP - - - -
2006-03-21 16:26:06 198.103.249.251 SGW5HQ1.INAC.GC.CA SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +SGW5HQ1.INAC.GC.CA 250 0 319 23 0 SMTP - - - -
2006-03-21 16:26:06 198.103.249.251 SGW5HQ1.INAC.GC.CA SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<roeschm@inac-ainc.gc.ca> 250 0 48 45 0 SMTP - - - -
2006-03-21 16:26:06 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+2.6.0++<BAY103-F423257C473EF350869FE4CED80@phx.gbl>+Queued+mail+for+delivery 0 0 80 0 9797 SMTP - - - -
2006-03-21 16:26:06 192.168.2.3 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 QUIT - - 0 0 4 0 9813 SMTP - - - -
2006-03-21 16:26:06 198.103.249.251 SGW5HQ1.INAC.GC.CA SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<davegru@wcb.nt.ca> 250 0 30 27 0 SMTP - - - -
2006-03-21 16:26:06 192.168.2.3 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 221+2.0.0+iq-file-2.corp.wcb.nt.ca+Service+closing+transmission+channel 0 0 71 0 10500 SMTP - - - -
2006-03-21 16:26:08 198.103.249.251 SGW5HQ1.INAC.GC.CA SMTPSVC1 YK-EXCH-2 192.168.5.23 0 DATA - +<s41fe11a.039@SGW5HQ1.INAC.GC.CA> 250 0 117 2480 813 SMTP - - - -
2006-03-21 16:26:08 198.103.249.251 SGW5HQ1.INAC.GC.CA SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - SGW5HQ1.INAC.GC.CA 240 1391 73 4 0 SMTP - - - -
2006-03-21 16:26:09 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 220+mailgate.gov.nt.ca+ESMTP+ready. 0 0 35 0 750 SMTP - - - -
2006-03-21 16:26:09 216.108.160.2 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 EHLO - yk-exch-2.corp.wcb.nt.ca 0 0 4 0 750 SMTP - - - -
2006-03-21 16:26:09 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250-igloo1.gov.nt.ca 0 0 20 0 1156 SMTP - - - -
2006-03-21 16:26:09 216.108.160.2 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 MAIL - FROM:<CaitlinC@wcb.nt.ca>+SIZE=4406 0 0 4 0 1156 SMTP - - - -
2006-03-21 16:26:09 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+Ok 0 0 6 0 1546 SMTP - - - -
2006-03-21 16:26:09 216.108.160.2 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 RCPT - TO:<bearfacts@gov.nt.ca> 0 0 4 0 1546 SMTP - - - -
2006-03-21 16:26:11 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+Ok 0 0 6 0 2265 SMTP - - - -
2006-03-21 16:26:11 216.108.160.2 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 DATA - - 0 0 4 0 2265 SMTP - - - -
2006-03-21 16:26:11 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 354+End+data+with+<CR><LF>.<CR><LF> 0 0 35 0 2640 SMTP - - - -
2006-03-21 16:26:13 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+Ok:+queued+as+75DE19032E 0 0 28 0 4062 SMTP - - - -
2006-03-21 16:26:13 216.108.160.2 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 QUIT - - 0 0 4 0 4078 SMTP - - - -
2006-03-21 16:26:13 216.108.160.2 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 221+Bye 0 0 7 0 4484 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 220+scmze005.ssan.egs-seg.gc.ca+ESMTP 0 0 37 0 375 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 EHLO - yk-exch-2.corp.wcb.nt.ca 0 0 4 0 375 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250-scmze005.ssan.egs-seg.gc.ca 0 0 31 0 469 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 MAIL - FROM:<CourtneyW@wcb.nt.ca>+SIZE=9732 0 0 4 0 469 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+sender+<CourtneyW@wcb.nt.ca>+ok 0 0 35 0 563 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 RCPT - TO:<OndrackA@DFO-MPO.GC.CA> 0 0 4 0 563 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+recipient+<OndrackA@DFO-MPO.GC.CA>+ok 0 0 41 0 657 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 DATA - - 0 0 4 0 657 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 354+go+ahead 0 0 12 0 750 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 250+ok:++Message+128826298+accepted 0 0 35 0 938 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionCommand SMTPSVC1 YK-EXCH-2 - 25 QUIT - - 0 0 4 0 953 SMTP - - - -
2006-03-21 16:26:14 205.194.19.89 OutboundConnectionResponse SMTPSVC1 YK-EXCH-2 - 25 - - 221+scmze005.ssan.egs-seg.gc.ca 0 0 31 0 1032 SMTP - - - -
2006-03-21 16:26:25 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +igloo1.gov.nt.ca 250 0 318 21 0 SMTP - - - -
2006-03-21 16:26:25 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +dmjskwhy7lkljbw 250 0 315 20 0 SMTP - - - -
2006-03-21 16:26:25 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 EHLO - +dmjskwhy7lkljbw 250 0 315 20 0 SMTP - - - -
2006-03-21 16:26:25 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<Saundra_Arberry@gov.nt.ca> 250 0 50 47 0 SMTP - - - -
2006-03-21 16:26:25 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<CaitlinC@wcb.nt.ca> 250 0 31 28 0 SMTP - - - -
2006-03-21 16:26:25 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 DATA - +<"AUTOANS-2a636fed.1142958359.arctic42.gov.nt.ca*"@MHS> 250 0 139 1916 500 SMTP - - - -
2006-03-21 16:26:25 216.108.160.10 igloo1.gov.nt.ca SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - igloo1.gov.nt.ca 240 1250 73 4 0 SMTP - - - -
2006-03-21 16:26:28 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<hostmaster@10-million-hits.com> 250 0 55 42 0 SMTP - - - -
2006-03-21 16:26:28 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<brendam@wcb.nt.ca> 250 0 30 27 0 SMTP - - - -
2006-03-21 16:26:28 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 MAIL - +FROM:<ayman_kassem@0500mail.com> 250 0 50 37 0 SMTP - - - -
2006-03-21 16:26:28 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 RCPT - +TO:<brente@wcb.nt.ca> 250 0 29 26 0 SMTP - - - -
2006-03-21 16:26:35 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 DATA - +<4088585808.20060321162610@10-million-hits.com> 250 0 131 2586 6250 SMTP - - - -
2006-03-21 16:26:35 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 DATA - +<3707831339.20060321162610@0500mail.com> 250 0 124 2597 6281 SMTP - - - -
2006-03-21 16:26:38 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - dmjskwhy7lkljbw 240 16062 131 2586 9500 SMTP - - - -
2006-03-21 16:26:38 88.9.152.54 dmjskwhy7lkljbw SMTPSVC1 YK-EXCH-2 192.168.5.23 0 QUIT - dmjskwhy7lkljbw 240 16093 124 2597 9515 SMTP - - - -
=====END SMTP LOG=====

Thanks again for the help.

Dice.
0
 
tymesCommented:
Well, first, you may not be forwarding messages appropriate... from the Subject: I will guess that you are fowarding it as inline text without message headers which these people will likely also want and need.   The easiest way to forward these messages is to wait for two and highlight them both and forward them (they will appear as attachments)... If I only have one to forward, I would select two, including one extraneous one which I remove from the attachments list... the messages have to be attachments for them to be full and complete.  -- This has nothing to do with the problem.  I have buttons in outlook that will not only forward the message as completely as is possible with Outlook/Exchange but send it to the proper email address and in one swift action.


In your logs, there were no references to the domain so you didn't find any reference there?   We should be looking for OutboundConnection*, from your email to them.  It looks to me you submitted the message a 3:44PM which would be 20:44 on the 17th and lasted until the 19th.   The logs were from an entirely different day -- the 21st..   But it does for two days so you should have lots of opportunity...

(I would send eeadmin a message asking them to edit out your logs from that message so they're not posted as is on the internet.  I don't have a problem about posting my own email addresses on the internet cuz I welcome people who want to try to spam me... but since you have lackluster spamfiltering, I would want the email addresses of some of your users removed.  Normally, I would just do 2 or 3 search and replaces to obsfucate email address somewhat and remove some ipaddresses before posting a log.  Most people here don't supply any information at all and doing any debugging is thwarted.)


Next, tackling this from their end rather than your end... I when to the command prompt and did an mx lookup for research.sybari.com and got
research.sybari.com     MX preference = 5, mail exchanger = res_relay.sybari.com
research.sybari.com     MX preference = 10, mail exchanger = mgate2.sybari.com

After trying to do TELNET res_relay.sybari.com 25  and to mgate2.sybari.com, ... I found neither worked exactly, like your for mailserver, so is that email address/subdomain address which defunct.  I would contact them for an updated/current email address (or get rid of all their contact information).   I would have thought they being in the email business would not be so stupid, but I was wrong.   I should have immediately checked the email address myself.  They have a problem or you somehow got some old no longer valid address and there is nothing wrong with you or your your configuration -- although it would nice to learn how to check the various logs and debug these sorts of things.


I do also notice more spam in your logs... mail from hostmaster@10-million-hits.com, doesn't sound very reputable to me.  Oh, god, it's a microsoft company.  Oh... but your spamfilter probably doesn't work that way... you accept EVERYTHING, including mail to non-existant users, and viruses, and then decide what is good or not then create more mail and blow-back when you bounce messages back...  I hate that.



0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
Diceman_01Author Commented:
Thanks for the tip about contacting an eeadmin.   I have done just that (http://www.experts-exchange.com/Community_Support/Q_21783235.html).   Also, thanks for helping me establish that it was a defunct email address.   I think that's the solution to the problem, so points to you.

For the discrepancy between the NDR and the logs, it is because it takes two days for an NDR to be generated, while I only turned on logging this morning.   As a consequence, I had to use the NDR from one e-mail and the log info from a second e-mail.   I can post the NDRs for the mails sent today on Thursday, if that would be of any further help in this.

Incindentally, the e-mail addresses came from the Sybari Advanced Spam Manager whitepaper (http://www.sybari.com/_Rainbow/Documents/ASM_WP_0504.pdf), page 8, the first and second questions.   The whitepaper itself is dated March 2004, but it is still actively linked to from the Sybari Product homepage (http://www.sybari.com/portal/alias__Rainbow/lang__en-US/tabID__3433/DesktopDefault.aspx).   I imagine that Sybari was purchased by Microsoft in that time, and no one thought to update the information.

Lastly, thanks for the tip about forwarding the junk mail to the company.   I'll employ that from now on.

So, thanks very much for all the help.   I'll start hunting around for a new place to be sending this stuff to in the future.   If it occurs to me, I will try to follow up on this question when I have the answer, so that future users can use this question as a resource.

Dice.
0
 
tymesCommented:
The use that subdomain for an email address on http://www.sybari.com/portal/alias__Rainbow/lang__en-US/tabID__70003589/DesktopDefault.aspx, something directly on their webpage in the support section and not some PDF from 2004.

(on any page, select Submit Virus on the Support drop down menu)

the email you are trying should probably work.
0
 
Diceman_01Author Commented:
Thanks for the follow-up.   I just spent an hour on the line with MS, but they were able to advise that the correct e-mail addresses are as follows:

for false negatives: spam.mail-filters@antigen.microsoft.com

and

for false positives: notspam.mail-filters@antigen.microsoft.com

I see what you're talking about on the Sybari webpage though, regarding the research.sybari.com subdomain.   All I can suggest is that the whole Sybari website should probably some offline, and redirect useres to an appropriate page in the microsoft site.

Thanks again for all your help.   It is much appreciated.

Dice.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

  • 3
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now