Solved

SMTP Queues

Posted on 2006-11-30
10
552 Views
Last Modified: 2010-03-06
I am having an issue with the SMTP queues being populated with hundreds of queues that are nothing to do with the business. The badmail folder is also being populated at a rapid rate.
I have been through the various articles on changing the access rights and also tested the server for an open relay.
I have up to date anti virus software and there is no viruses on the network.
I am however getting some viruses reporting in symantec mail security which are being removed.
I have a small business server 2000 which has is fully up to date with all the critcial updates.
The server is 2000 SP4 and exchange is SP3.
I would appreciate your urgency on this matter.
Regards
Davinder
0
Comment
Question by:mahajand
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
10 Comments
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 18050459
Sounds like you are under an NDR attack.
You need my spam cleanup article to deal with it.
http://www.amset.info/exchange/spam-cleanup.asp

Unfortunately Exchange 2000 doesn't deal with this type of attack very well. You will need a third party tool that can do directory lookup to put in front of Exchange to deal with the messages.

GFI Mail Essentials can do that, as can Vamsoft ORF. Both have trial version so you could download that and install it to help with dealing with the emergency. Of the two, Vamsoft can be the cheaper as it is priced per server, not per user.

Simon.

0
 
LVL 8

Expert Comment

by:nitadmin
ID: 18051227
You are under an NDR attack. If you look at the messages stuck in these Queues. You will notice it addressed to Postmaster.

I recommend that you get a Barracuda Spam Filter Appliance.

You other options is to Configure your Exchangse Server's

Sender, Recipient, Connection, IMF, and RBL filters.

Cheers,
NITADMIN
0
 
LVL 104

Expert Comment

by:Sembee
ID: 18051434
NITADMIN - this is Exchange 2000. It doesn't have recipient filtering, IMF or RBL support.

A barracuda is quite a significant investment, when for US$200 you can deal with the NDRs by using a tool that can do recipient filtering.

Simon.
0
Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

 

Author Comment

by:mahajand
ID: 18052373
I have configured an SMTP connector which I understand overwrites the smtp virtual server.
Is there any specfic settings I need to add.
At the moment under address space I have type: SMTP - Address:  * - Cost: 1
Under the general tab I have added a bridgehead with the server name and the virtual server as default SMTP virtual server.
I am also looking into installing the some third party tool with dealing with the NDR attack.
0
 
LVL 8

Expert Comment

by:nitadmin
ID: 18055150
"SMTP connector which I understand overwrites the smtp virtual server."

This statment is not true. The SMTP connector works with the smtp virtual server.

Cheers,
NITADMIN
0
 
LVL 104

Expert Comment

by:Sembee
ID: 18055175
Its actually the other way round.
If you have a smart host set on the SMTP virtual server that will be used for everything, despite what the Exchange server may find for itself.

Are you setting up an SMTP Connector as part of my clean up article? If not, then I fail to see why you are doing this, as it doesn't help with dealing with the problem at all.

Simon.
0
 

Author Comment

by:mahajand
ID: 18104580
I have installed the GFI mail essentials software.
Is there  any configuration changes I need to make in the software?
I will monitor the queues and the badmail folder over the course of the next three days.
0
 

Author Comment

by:mahajand
ID: 18107935
The queues and the badmail folder has started to populate at a rapid rate again.
I will read through the documentation with regards to the GFI, but would appreciate some pointers.
0

Featured Post

Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
This video discusses moving either the default database or any database to a new volume.

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question