?
Solved

exchange not delivery all emails - MSExchangeTransport

Posted on 2009-04-14
14
Medium Priority
?
364 Views
Last Modified: 2012-05-06
Hi
I am having a problem where some of my accounts are not reciving email,
and some are reviving email very sporadically.
I am getting a lot of MSExchangeTransport errors in event viewer.
event id 3018, 7004.
I saw a previus artivle about filtering but this seems to be setup fine.
I was getting mail fine myself, but now my account is getting none(however i have differnt domain for my mail, i.e second domain added to reciepeint poilicies).
Thanks
Stephen


Would this b
0
Comment
Question by:cstephen100
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
14 Comments
 
LVL 8

Assisted Solution

by:greesh_hem
greesh_hem earned 200 total points
ID: 24136728
This is one of two things.

1. DNS problems.
2. Spam.

If the emails are not ones that you normally would expect to go through your server and you have significant amounts of messages in the queues then spam attack is the likely cause.

If your queues are clear or have very small numbers of messages then it could be DNS.
Verify that you have internal DNS servers listed in the DNS configuration on the Exchange server - they should be pointed at the domain controllers only.
You may then need to configure forwarders on your DNS Server configuration on the domain controllers to use your ISPs DNS servers.
0
 

Author Comment

by:cstephen100
ID: 24137456

Hi,
  I looked at the queues in esm,  and there is literrally 2699 entries in here, most of these are for domains ending in .tw,
i.e  1111.com.tw,  123.job.tw etc... (i have attached image to show you what i mean)
this to me doesnt look to good :-(.,
Is this a spam attack or related?
how do i go about stopping this?
hope you can help here..
thanks
Stephen

queses.JPG
0
 
LVL 65

Accepted Solution

by:
Mestha earned 1800 total points
ID: 24137628
Your server is being abused.
You should not have those numbers of messages in there. You need to find out how and then close the hole.

Start with my spam cleanup article: http://www.amset.info/exchange/spam-cleanup.asp

Basically it is either an open relay, authenticated relay or NDR attack.

Simon.
0
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

 

Author Comment

by:cstephen100
ID: 24139986

thanks for replies,
i followed guides above thanks,
however,
the smtp virtual connector is very slow starting, i mean esm is running but not responding for 4hrs approx, is this normal?
thanks
stephen
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24140055
If the server is being abused then that is not unusual.
ESM is notorious for struggling to show the true extent of the queues after the server has been abused.

Simon.
0
 

Author Comment

by:cstephen100
ID: 24140085
cheers,
what i meant to ask you, is should i let it start normally, or is there other way?
if i have to wait thats fine.
thanks
stephen
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24142807
You will need to wait, things will be very sluggish as the server is probably trying to process many 1000s of messages.

Hopefully you have blocked port 25 on your firewall so that new messages do not continue to come in.

Simon.
0
 

Author Comment

by:cstephen100
ID: 24143284
hi guys,
i went though steps on above links, and everything seems to be set so server is not relay server,
however,
my server still seems to be targetted by the spammers, also when a delete queues i have loads of empty queses as shown in picture.
  Maybe i should open seperate question for this?  but bascially is there more i have to do to stop server been used for spam,
Also the no external domains are reciving emails even though it looks like there sent?
thanks
stephen

0
 

Author Comment

by:cstephen100
ID: 24143352
i feel i should award points here and open new question for new issues?
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24143404
If the queues are empty, then that is fine. It takes Exchange a while to remove the empty queues from the list. What you need to watch for is messages in the queues.

Simon.
0
 

Author Comment

by:cstephen100
ID: 24143430
there seems to be messages going into the queses again :-(,
and external domains dont seem to be recieving mails, plus I checked www.dnsstuff.com and it told me my domain is blacklisted,
doesnt sound good,
thanks for help Simon
Im under a bit of pressure with it,
cheers again
Stephen
0
 
LVL 65

Expert Comment

by:Mestha
ID: 24143546
Domains do not get blacklisted, hosts do.
You now have two quesitons running, which means there will be some duplication. As I wrote in the other question - you need to close port 25 to ensure that no new emails are coming in.

Simon.
0
 

Author Comment

by:cstephen100
ID: 24146126

Hi simon,
I woke this morning and was pleasently suprised to see that the queses had reduced,
and email seems to be working fine, i am being pestered a bit about missing mails from yesterday but ill get over that :-).
Thanks ever so much!
Stephen

P.s:  on a note, they need to get decent AV for sever and mail server, Is there any you would recommend? i noticed avast does 30 day trial.
thanks again
Stephen

0
 
LVL 65

Expert Comment

by:Mestha
ID: 24146176
AV - you pays your money and takes your choice. I usually suggest either Forefront or GFI Mail Security. Both have multiple engines. You want something different to what is on your workstations.

The messages would go over time on their own, as they time out after 48 hours. However that wouldn't stop your server from being blacklisted.

Simon.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
New style of hardware planning for Microsoft Exchange server.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Suggested Courses
Course of the Month12 days, 3 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question