Link to home
Start Free TrialLog in
Avatar of Edgerock
Edgerock

asked on

Is someone on my domain sending out spam? Exchange Server is receiving a lot of failure notices

I set up some spam filtering software on an Exchange 2003 server and I have been monitoring the "bad mail" folder daily to make sure it doesn't block anything good.  This morning I noticed litterally hundreds of "Failure Notice" emails from "MAILER-DAEMON" at many different domains.  It appears all these messages say they originated from  [random name]@[mydoamin].com.  The server is not an open relay, and I am checking the queues for anything suspicious, but see nothing in the way of outgoing mail coming from my server.

Is this a sign that someone on the domain is sending out spam? What's the best way to track it down if this is the case?
ASKER CERTIFIED SOLUTION
Avatar of Sembee
Sembee
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of MrLonandB
MrLonandB

One thing to try. Go to Message Tracking Center. Run a query on an intended recipient (if you can tell from the Failure Notice) and see who the sender is. Or whatever information you have from the failure notice, see if you can query it in some fashion from the MTC to determine any origination information.
Avatar of Edgerock

ASKER

Thanks Simon--when i checked the MTC on the server and watched the queues for a while and saw nothing suspicious I figured that's what was going on. Better safe than sorry, though.