Solved

ject: Delivery Status Notification (Failure)

Posted on 2006-06-20
5
432 Views
Last Modified: 2013-11-15
I have an Exchange 2003 installed and working.  However, recently one user is receiving multiple e-mails on a daily basis notifying him of delivery failure.  An example of the e-mail message is below:

From: postmaster@kancharla.com [mailto:postmaster@kancharla.com]
Sent: Sunday, June 18, 2006 5:45 PM
To: zmnmyskl@goldstandardchorus.org
Subject: Delivery Status Notification (Failure)

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

       asnbrq@kancharla.com

The strange thing is that my user never sent a message to these users.  When I look in their sent items, the is no trace of this message being sent.  I have ran multiple virus scans and spyware scans on his local computer and come up with nothing.

Is there any type of report that I can run on exchange to find out where these messages are originating?  Any suggestions on how to resolve this issue?  

I have 10 other e-mail users and they are not having this problem.  They receive the occasion junk mail, but that is it.  Please advise.
0
Comment
Question by:robertjwilsoncpa
5 Comments
 
LVL 4

Expert Comment

by:ganongj
ID: 16942513
Hi Robert,

yes, you can use the tool in Exchange System Manager to find out it's path, and what's happening with it.
The  tool is called "Message Tracking Center"..  fill in the appropriate items there, and your message will appear below, double-click on the message you want to see the tracking for, and you will see the detail of what is happening with your message when it leaves.

Jim
0
 
LVL 35

Expert Comment

by:rakeshmiglani
ID: 16942514
check the smtp header of this email. this appears to be spam. the header would list the ip of the originating address
0
 
LVL 31

Accepted Solution

by:
LeeDerbyshire earned 500 total points
ID: 16942915
I would guess that a spammer has sent an email to the asnbrq@ address , pretending that the email's sender was your zmnmyskl@ address.  The asnbrq@ address has expired by the look of things, so the NDR comes back to your zmnmyskl@ address.  They probably got the email addresses by harvesting Web pages like this one.  I don't know if those are real email addresses in your original message, but it's not a good idea to expose them like that, I'm afraid.  This is where they get the addresses from these days.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Healthcare organizations in the United States must adhere to the guidance of both the HIPAA (Health Insurance Portability and Accountability Act) and HITECH (Health Information Technology for Economic and Clinical Health Act) for securing and protec…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
Using Adobe Premiere Pro, the viewer will learn how to set up a sequence with proper settings, importing pictures, rendering, and exporting the finished product.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now