Solved

Exchange 2003 SMTP security lockdown procedures

Posted on 2007-03-25
1
2,243 Views
Last Modified: 2012-05-05
Im using Small Business Server for exchange 2003 mail management.

Periodocially i find that my server is being used to relay messages by spammers.

Is there a consise checklist of security steps i should follow?


0
Comment
Question by:mbalsam
1 Comment
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 18788341
Exchange 2003 is relay secure out of the box, so something has been changed.

There are three main ways that an Exchange server can be abused...

- configuration error on the SMTP virtual server or SMTP Connector turns the machine in to an open relay

- authenticated relaying - where the administrator password has been compromised and is being used to allow messages to be sent through the server.

- NDR spam - this is where messages are sent to your server with invalid email addresses on purpose. Your server then tries to bounce them back to the "sender" - who is spoofed and is the real target.

For NDR spam you should deploy recipient filtering and the tarpit.
http://www.amset.info/exchange/filter-unknown.asp

For authenticated user relaying, you need to look at changing the settings.
http://www.amset.info/exchange/smtp-relaysecure.asp

Finally, for checking whether the machine is an open relay, see my article here:
http://www.amset.info/exchange/smtp-openrelay.asp

Simon.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question