[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

returned email over 2 months late, running exchange and symantec smtp gateway 4  where was the problem?

Posted on 2008-10-04
7
Medium Priority
?
598 Views
Last Modified: 2013-12-09
Few days ago our email system was flooded with several thousand emails in a matter of minutes. All were bounce backs of legitmates emails sent out several months ago.

I am running Symantec smtp gateway 4 for AV filtering and exchange 2003.

Question iwhere were the bounce backs all this time, why did i get them now and not when i was supposed to. I know the emails came from the gateway but i'm not sure how to tell if they were generated at the original time and never delivered, generated a few days ago when it happened (if so, why did it take 2 months for it to generate a ndr) or could there be other reasons altogether.

I went into the gateway logs for one of the bounce backs. When i sent it originally the log states that Action:message delivery attemp failed , Last response: could not connect to server. Then i received a ndr a few days ago after sending it out 2 months ago.

Also, not sure if its relevant but i am running BGP and i had a failure of my primary ISP an hour before all this happened. The session wasn't shutdown properly and we never kicked over to our secondary isp. Our primary came back up within 2 minutes.

Big question, are are my bounce backs so late.
0
Comment
Question by:Cyclonus
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
7 Comments
 
LVL 2

Expert Comment

by:Highspade
ID: 22643566
what is your smtp virtual servers email expiration timeout setting? you can find the information on the delivery tab.
0
 

Author Comment

by:Cyclonus
ID: 22643574
Expiration timeout setting is 2 days. Just to clarify, the NDR's are for old messages but the NDR's themselves appear to have been generated at the time we received them.
0
 
LVL 2

Expert Comment

by:Highspade
ID: 22643618
0
Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

 

Author Comment

by:Cyclonus
ID: 22643693
Highspade,

I having been reading about the greylisting issue as well. Just earlier find a pretty large thread including some work arounds. My problem is how to confirm it is in fact a greylisting issue. I will contact a few of the companys i had ndrs for and try to find out if they use grey listing. Only reason i beilieve it isn't grey listing is one of the ndrs was from an email sent to a yahoo account. According to yahoo they don't use grey listing. Also for the ndr's to suddenly start going nuts, it requires a restart of the server, smtp service or mail storage group. I can't seem to find any indication of either of those being restarted. Event logs dont show anything right before it happened.  So i'm still looking.
0
 
LVL 1

Expert Comment

by:livegirllove
ID: 24751689
Hmm.  I just had the same thing happen at a client site.  recived 3 NDRs all generated at close tothe same time for emails sent and accorfing to message tracking rejected up to 2 monthes ago.  I dont use any of the products above.  Exchange 2003 fully patched.  2 day exiration on delivery attempts.
0
 
LVL 1

Accepted Solution

by:
livegirllove earned 2000 total points
ID: 24751696
you may want to look at
http://forums.whirlpool.net.au/forum-replies-archive.cfm/896965.html

and

http://support.microsoft.com/default.aspx?scid=kb;EN-US;934709

says exchange 2003 borks on greylisted addresses from time to time.  That hotfix doesnt look like exactly the issue though..
0
 
LVL 1

Expert Comment

by:livegirllove
ID: 25755021
thanks but I think Highspade had the answer first...
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This post contains step-by-step instructions for setting up alerting in Percona Monitoring and Management (PMM) using Grafana.
The main intent of this article is to make you aware of ‘Exchange fail to mount’ error, its effects, causes, and solution.
This video demonstrates how to use each tool, their shortcuts, where and when to use them, and how to use the keyboard to improve workflow.
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question