Open email Relay, Email storm even when NO internet, wrong diagnosis?
Posted on 2006-06-20
350 to 900 new rubbish emails are being generated on my exchange 2003 server which is patched up to date.
I used 3 different open relay tests that all returned a negative on the relay test.
4 different antivirus companies couldn't find any email sending virus on the system.
After disconnecting the internet - just one donaim controller connected to the exchange box through a switch - still observing 350 to 900 new emails per minute.
We have a satelite connection to the web with a 33.6K modem as a return path.
I now discover an open relay function is happening 12 days after first discovering the email storm. Possibly because the Exchange server didn't return the test email in the alloted time for the open relay test. I manually telneted into the front end of the exchange server and manually setup an email with the SMTP commands.
If this is all the whole issue is about - how come I continued to observe 350 to 900 emails per minute being added to the outgoing cue in Exchange Manager after passing through the awaiting directory lookup, pending submission and waiting to be routed while now being connected to the internet?
Would I be correct in assuming Exchange precached the emails so that when I isolated the 2 servers, exchange still continued to process emails from the Exchange Manager Queue view, so it looked like they were being freshly generated?
The satelite has about 1.5k to 400K download depending on Telstra ( that's another story). The outgoing modem is only 33.6K and gets bogged down. Would this allow the spam to backup in the exchange server.
Thank you for your feedback and help.