Exchange Queue filling up?

Got a problem here I wanted to see if anyone had ever come across. I have a small insurance company (8 people), the outbound Queue on their exchange server keeps filling up to the point where it stops processing mail. They were getting blacklisted bounceback emails so I figured that it was a virus sending out spam from their network. I found that virus on a PC that they said had virus problems and removed it. I filled out some stuff to get them delisted ,I cleared out the queue, restarted the virtual server and it appeared to be working as of last week. Now today the queue was full again and it wasnt working.

I then checked each PC for the virus and cleaned them all anyway but didn't find anything. The problem keeps happening. There's no way that they sent 22,543 messages to yahoo overnight while there are closed so it looks like either the virus is still there ion some way or there is some other problem. What can I do? Once the queue gets to a certian point it stops sending and recieving legitimate mail.
LVL 2
Axis52401Security AnalystAsked:
Who is Participating?
 
JoWickermanConnect With a Mentor Commented:
Hi,

Are you happy with the solution? If so, you can close the question and award points.

Cheers.
0
 
leegclystvaleCommented:
Is it acting as a relay? Check these settings
http://support.microsoft.com/kb/895853 and select
"If your Exchange computer is configured as an open mail relay that sends unsolicited commercial e-mail"
0
 
JoWickermanCommented:
Hi Jason0923,

It seems as though the Exchange server might be open for relaying?

http://www.checkor.com/

Test your IP and let me know?

Cheers.
0
 
Axis52401Security AnalystAuthor Commented:
I have checked the Relay settings and the server isn't configured as an open relay and here are the results from the http://www.checkor.com/  I have to keep stopping the Virtual server, deleting the queue and restarting it to keep the company's email running. I would appreciate eny help.

Thank you

220 QUAM2K3FS.quam.local Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at Tue, 11 Nov 2008 09:04:42 -0600
HELO ortest.checkor.com
250 QUAM2K3FS.quam.local Hello [204.16.252.112]
RSET
250 2.0.0 Resetting
MAIL FROM: test@checkor.com
250 2.1.0 test@checkor.com....Sender OK
RCPT TO: test1@checkor.com
550 5.7.1 Unable to relay for test1@checkor.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM:
501 5.5.4 Invalid Address
RCPT TO: test1@checkor.com
503 5.5.2 Need Mail From: first


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: test1@checkor.com
550 5.7.1 Unable to relay for test1@checkor.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: test1@checkor.com
550 5.7.1 Unable to relay for test1@checkor.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: test1@mail.quamins.com
550 5.7.1 Unable to relay for test1@mail.quamins.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: "test1@test.com"@mail.quamins.com
550 5.7.1 Unable to relay for "test1@test.com"@mail.quamins.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: @mail.quamins.com:spamtest@checkor.com
550 5.7.1 Unable to relay for spamtest@checkor.com
0
 
JoWickermanCommented:
Ok, so the server is not open for relaying... Then it has  to be a virus... Did you check the Exchange server itself for viruses?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.