Solved

High volume of outgoing emails being relayed through Exchange

Posted on 2008-10-07
10
475 Views
Last Modified: 2013-11-30
Hi there, we have a HUGE amount of email (which I've only just noticed) being sent out through our client's exchange server.

I logged into OWA, and noticed there was arround 40000 emails in the inbox, nearly all of them were bouncebacks from various people. I then checked Exchange tracking centre, and its just spewing out loads of emails.

I'm pretty sure open relay isn't enabled on the server, as I've compared the config with another SBS server.

is there anyway I can track where these emails are being sent from? Perhaps they are coming from a client with a virus on.

I'm surprised they haven't been blacklisted...

ANy help would be much appreciated.
0
Comment
Question by:dougb9429
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
10 Comments
 
LVL 17

Expert Comment

by:sgsm81
ID: 22659980
Check any firewall rules on port 25 to see if it is locked to a particular IP range.

Check the e-mail headers - http://www.stopspam.org/email/headers.html

Do you have e-mail antivirus client for outlook or similar - might be worth a scan..
0
 

Author Comment

by:dougb9429
ID: 22660013
Hi there, thanks for your reply.

Is there any way I can check the headers of the emails that have been sent out? Either thru OWA or through Exchange??

I will kick off a scan straight away.
0
 
LVL 17

Expert Comment

by:sgsm81
ID: 22660054
Hi

Have you enabled e-mail journalling at all ? if so this would keep a copy of everything that was sent ?

Do you use a hosted anti spam solution or similar e.g. e-mailsystems ?
0
Why You Need a DevOps Toolchain

IT needs to deliver services with more agility and velocity. IT must roll out application features and innovations faster to keep up with customer demands, which is where a DevOps toolchain steps in. View the infographic to see why you need a DevOps toolchain.

 

Author Comment

by:dougb9429
ID: 22660076
No journaling isn't enabled...

And no, we use GFI Mail Essentials for anti spam.

I suppose if I enable journaling now, it will still pick up email, then I guess I could read the headers of that?
0
 

Author Comment

by:dougb9429
ID: 22660285
I've enabled journaling, and it's picking up other emails, but all the emails being sent from the administrator account are not being journaled, despite them all showing in the exchange tracking centre.
0
 
LVL 17

Expert Comment

by:sgsm81
ID: 22660490
What version of exchange are you running and how have you enabled journalling ?

(sorry but dependent on the version there are a few ways to do it).

Also can you see if the mails are being sent from one account ? if so is it possible to disable that account's mailbox whilst the problem is diagnosed.
0
 

Author Comment

by:dougb9429
ID: 22660542
It's 2003 on an SBS Server (SP2)

I set up a new user for journaling, right clicked on the mailbox store, and selected archive sent/received messages.

The account is actually the administrator account. It has a secondary email called postmaster@ and all the emails are being sent from there.
0
 
LVL 17

Expert Comment

by:sgsm81
ID: 22666901
Did you find anything from the e-mail headers which indicates the sender/recipient of mail sent/received ?

Have you checked your 2003 server to ensure its not a relay?

I'd also consider enabling advanced journaling to cover BCC, Distribution lists etc

http://www.microsoft.com/downloads/details.aspx?familyid=e7f73f10-7933-40f3-b07e-ebf38df3400d&displaylang=en
0
 
LVL 2

Accepted Solution

by:
DSchel01 earned 500 total points
ID: 22668387
Most likely the they are NDR messages caused by NDR (or back scatter) spam.

Ensure you are on at least the latest build of GFi MailEssentials 12 (20080623) which includes the NDR spam functionality. Make sure to leave the New Senders functionality disabled, but set the action to delete. This will prevent NDR spam from being received by end users in future.

Also, if you have maintenance consider upgrading to MailEssentials 14. This version of MailEssentials includes a new antispam engine, spamrazer, which considerably improves the performance of MailEssentials spam detection. MailEssentials 14 can also filter directory harvesting emails at the protocol level, which will greatly reduce the amount of email accepted by your mail server.

More information:
How to check for NDR spam (BackScatter)
http://kbase.gfi.com/showarticle.asp?id=KBID003322

What's new in GFI MailEssentials 14 for Exchange/SMTP?
http://kbase.gfi.com/showarticle.asp?id=KBID003400
0
 

Author Closing Comment

by:dougb9429
ID: 31503817
After uninstalling and reinstalling GFI it seemed to work! Thanks for putting me on the right track!
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question