Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Relay or zombie, spam problem

Posted on 2007-10-08
5
Medium Priority
?
1,393 Views
Last Modified: 2008-01-09
Hello Experts,

I have an exchange 2007 server with 2 autorithative domains accepted. I have forefront for exchange servers installed on this computer and deactived IMF because people didn't receive emails from outside.

Today i saw in the mail spooler many mails with blank sender to externals domain. I realize a abuse.net open relay test and no error received. My exchange isn't relaying.

Next day i'm planning to scan all possible computers to find a zombie, but could be a configuration error of my exchange? what could i reconfigure to repair this mistake?

Thanks in advance.
0
Comment
Question by:apendes
  • 2
4 Comments
 
LVL 3

Expert Comment

by:mhequipit
ID: 20035855
What do you have setup for relay?  
0
 

Author Comment

by:apendes
ID: 20036051
Sorry, but i dont undestand you.

I test my server on http://zmailer.org and this are the results:

Testing MX server: mail.mydomain.com
Address lookup did yield following ones:

  IPv4 MyIpAddress

Testing server at address: IPv4 MyIpAddress
[ CONNECTED! ]

 220 mail.mydomain.com Microsoft ESMTP MAIL Service ready at Mon, 8 Oct 2007 20:31:06 +0200
 EHLO z2.cat.iki.fi
 250-mail.mydomain.com Hello [212.16.98.133]
 250-SIZE
 250-PIPELINING
 250-DSN
 250-ENHANCEDSTATUSCODES
 250-X-ANONYMOUSTLS
 250-AUTH GSSAPI NTLM LOGIN
 250-X-EXPS GSSAPI NTLM
 250-8BITMIME
 250-BINARYMIME
 250-CHUNKING
 250 XEXCH50

Excellent! It speaks ESMTP!

 MAIL FROM:<>
 250 2.1.0 Sender OK

Fine, it accepts NULL return-path as is mandated by RFC 2821 section 6.1

 RSET
 250 2.0.0 Resetting
 MAIL FROM:<postmaster@z2.cat.iki.fi>
 250 2.1.0 Sender OK
 RCPT TO:<postmaster@mail.mydomain.com>
 550 5.7.1 Unable to relay

Eh ? What ? No ``postmaster'' supported there ? That violates RFC 2821 section 4.5.1.

Apparently OK!

Another online test:
Mail relay testing
Connecting to 80.xx.xxx.xx for relay test...
<<< 220 mail.mydomain.com Microsoft ESMTP MAIL Service ready at Mon, 8 Oct 2007 20:39:22 +0200
>>> HELO antispam-ufrj.pads.ufrj.br
<<< 250 mail.mydomain.com Hello [146.164.48.5]
Relay test 1
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <spamtest@antispam-ufrj.pads.ufrj.br>
<<< 250 2.1.0 Sender OK
>>> RCPT TO: <relaytest@antispam-ufrj.pads.ufrj.br>
<<< 550 5.7.1 Unable to relay
Relay test 2
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <spamtest@antispam-ufrj.pads.ufrj.br>
<<< 250 2.1.0 Sender OK
>>> RCPT TO: relaytest@antispam-ufrj.pads.ufrj.br
<<< 550 5.7.1 Unable to relay
Relay test 3
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <spamtest>
<<< 501 5.1.7 Invalid address
>>> RCPT TO: <relaytest@antispam-ufrj.pads.ufrj.br>
<<< 503 5.5.2 Need mail command
Relay test 4
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <> 
<<< 250 2.1.0 Sender OK
>>> RCPT TO: <relaytest@antispam-ufrj.pads.ufrj.br>
<<< 550 5.7.1 Unable to relay
Relay test 5
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <spamtest@[80.xx.xxx.xx]>
<<< 501 5.1.7 Invalid address
>>> RCPT TO: <relaytest@antispam-ufrj.pads.ufrj.br>
<<< 503 5.5.2 Need mail command
Relay test 6
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <spamtest@xx.Red-80-xx-xxx.staticIP.xx-xxx.net>
<<< 250 2.1.0 Sender OK
>>> RCPT TO: <relaytest@antispam-ufrj.pads.ufrj.br>
<<< 550 5.7.1 Unable to relay
Relay test 7
>>> RSET
<<< 250 2.0.0 Resetting
>>> MAIL FROM: <spamtest@[80.xx.xxx.xx]>
<<< 501 5.1.7 Invalid address
>>> RCPT TO: <relaytest%antispam-ufrj.pads.ufrj.br@[80.xx.xxx.xx]>
<<< 421 4.7.0 Too many errors on this connection, closing transmission channel
0
 

Author Comment

by:apendes
ID: 20040041
Hello experts,

I found the solution searching in EE. The article was http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/Windows_64-bit/Q_22679955.html?sfQueryTermInfo=1+2007+exchang+queue+spam from expert tigermatt.

I only activated this IMF option (Recipient filtering - Block messages sent to recipients not listed in the GAL) because with all activated i didn't receive mail in all accounts. Can someone recommend what filters can i enable and their config?

Thanks.

0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 20237824
PAQed with points refunded (500)

Computer101
EE Admin
0

Featured Post

Free recovery tool for Microsoft Active Directory

Veeam Explorer for Microsoft Active Directory provides fast and reliable object-level recovery for Active Directory from a single-pass, agentless backup or storage snapshot — without the need to restore an entire virtual machine or use third-party tools.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Mailbox Corruption is a nightmare every Exchange DBA wishes he never has. Recovering from it can be super-hectic if not entirely futile. And though techniques like the New-MailboxRepairRequest cmdlet have been designed to help with fixing minor corr…
Exchange database can often fail to mount thereby halting the work of all users connected to it. Finding out why database isn’t mounting is crucial and getting the server back online. Stellar Phoenix Mailbox Exchange Recovery is a champion product t…
This video discusses moving either the default database or any database to a new volume.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question