how do i check if my exchange server is spoofing or sending out spam?

Posted on 2007-10-18
Last Modified: 2010-12-14
how do i check if my exchange server is spoofing or sending out spam?
Question by:xpconsult
    LVL 32

    Expert Comment

    (1) Check the mail smtp queues in Exchange System Manager to see if there is unusual activity.

    (2) Check your server at

    (3) See if your server's IP is listed with any RBL:

    (4) Examine any samples submitted by users to see where they originated.

    (5) In case you need to secure your server:

    Author Comment

    I had 4k email going out and 338 active connections,  we only have 4-5 users so i would call this very high and very bad.  
    LVL 32

    Accepted Solution

    That is certainly not good. You should determine the origin of some of those mails. Assuming you have closed any possibility of an open relay, it is likely you are the victim of an NDR flood, i.e. junk mail sent to non-existent users on your machine, causing hundreds of NDRs to be generated.

    Probably the most effective tool to stop this is to not accept mail for non-users. See:

    Also look into tarpitting and RBL filtering.

    Some useful links:

    LVL 32

    Expert Comment

    Thanks and good luck.

    Featured Post

    Threat Intelligence Starter Resources

    Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

    Join & Write a Comment

    Suggested Solutions

    Learn more about how the humble email signature can be used as more than just an electronic business card. When used correctly, a signature can easily be tailored for different purposes by different departments within an organization.
    Easy CSR creation in Exchange 2007,2010 and 2013
    In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
    The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

    730 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now