wl6538
asked on
Exchange 2007 routing spam but it is not an open relay
Dear experts,
I am experiencing a strange spam issue with my Exchange 2007 server (with the latest service pack and rollups) recently.
My config is:
Exchange 2007 SP1 with latest rollup (x64)
Windows Server 2008 x64
TrendMicro ScanMail (for spam and AV filtering)
I have checked that I am NOT an open relay by telneting to exchange port 25.
Also I have set Accepted Domains in Hub Transport and it is limited to my own domains only.
My problem is:
I am getting outgoing spam from my exchange server on the outgoing SMTP connector the frequency is of this problem is about 3 to 4 spam a day that went thru my outgoing SMTP connector.
Based on what I see from the message tracking tool, I can see that the spam will come thru the incoming SMTP first, destined to one of our real email addresses (as well as a bunch of other non-local email addresses in the CC: field) local to our domain, the spam will then get Quarantined by the content filtering using SCL rating of 7 for our exchange server.
However the spam message will somehow get thru to our outgoing SMTP connector and the message get sent to the non-local recipients in the CC: field
Please find below outgoing and incoming SMTP logs and the relevant part of message tracking log, as well as the header of the spam message itself.
Some notes:
For illustration purpose our domain is mydomain.com (public) and mydomain.local (LAN)
Our exchange mail server is called SPOCK
In these logs I have changed the real user name to real_local_user
Our ISPs SMTP smart host I used for outgoing mail is from fluidata.co.uk
The spammers are spoofing hmrc.gov.gov.uk in this case
Here are the logs:
SMTP receive log:
2009-04-29T09:47:38.466Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,0,1 92.168.116 .4:25,123. 18.150.215 :4384,+,,
2009-04-29T09:47:38.466Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,1,1 92.168.116 .4:25,123. 18.150.215 :4384,*,SM TPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDom ainSender AcceptRoutingHeaders,Set Session Permissions
2009-04-29T09:47:38.467Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,2,1 92.168.116 .4:25,123. 18.150.215 :4384,>,"2 20 spock.mydomain.local Microsoft ESMTP MAIL Service ready at Wed, 29 Apr 2009 10:47:37 +0100",
2009-04-29T09:47:39.036Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,3,1 92.168.116 .4:25,123. 18.150.215 :4384,<,HE LO hmrc.gov.uk,
2009-04-29T09:47:39.037Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,4,1 92.168.116 .4:25,123. 18.150.215 :4384,>,25 0 spock.mydomain.local Hello [123.18.150.215],
2009-04-29T09:47:39.608Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,5,1 92.168.116 .4:25,123. 18.150.215 :4384,<,MA IL FROM: <operator_num_83wgf@hmrc.g ov.uk>,
2009-04-29T09:47:39.608Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,6,1 92.168.116 .4:25,123. 18.150.215 :4384,*,08 CB96538CAC 4E8C;2009- 04-29T09:4 7:38.466Z; 1,receivin g message
2009-04-29T09:47:39.608Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,7,1 92.168.116 .4:25,123. 18.150.215 :4384,>,25 0 2.1.0 Sender OK,
2009-04-29T09:47:40.261Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,8,1 92.168.116 .4:25,123. 18.150.215 :4384,<,RC PT TO: <real_local_user@mydomain. com>,
2009-04-29T09:47:40.264Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,9,1 92.168.116 .4:25,123. 18.150.215 :4384,>,25 0 2.1.5 Recipient OK,
2009-04-29T09:47:40.812Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,10, 192.168.11 6.4:25,123 .18.150.21 5:4384,<,D ATA,
2009-04-29T09:47:40.813Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,11, 192.168.11 6.4:25,123 .18.150.21 5:4384,>,3 54 Start mail input; end with <CRLF>.<CRLF>,
2009-04-29T09:47:42.130Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,12, 192.168.11 6.4:25,123 .18.150.21 5:4384,>,2 50 2.6.0 <000801c9c989$38c6e552$020 1a8c0@c-ff c4b14a8d7f 4> Queued mail for delivery,
2009-04-29T09:47:42.691Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,13, 192.168.11 6.4:25,123 .18.150.21 5:4384,<,Q UIT,
2009-04-29T09:47:42.691Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,14, 192.168.11 6.4:25,123 .18.150.21 5:4384,>,2 21 2.0.0 Service closing transmission channel,
2009-04-29T09:47:42.692Z,S POCK\Defau lt SPOCK,08CB96538CAC4E8C,15, 192.168.11 6.4:25,123 .18.150.21 5:4384,-,, Local
SMTP send log:
2009-04-29T09:47:42.269Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,0,,89.105 .96.56:25, *,,attempt ing to connect
2009-04-29T09:47:42.277Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,1,192.168 .116.4:203 7,89.105.9 6.56:25,+, ,
2009-04-29T09:47:42.295Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,2,192.168 .116.4:203 7,89.105.9 6.56:25,<, "220 smtp2.fluidata.co.uk ESMTP Sendmail 8.13.8/8.13.8; Wed, 29 Apr 2009 10:49:43 +0100",
2009-04-29T09:47:42.295Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,3,192.168 .116.4:203 7,89.105.9 6.56:25,>, EHLO spock.mydomain.com,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,4,192.168 .116.4:203 7,89.105.9 6.56:25,<, "250-smtp2 .fluidata. co.uk Hello mydomain.com.fluidata.co.u k [mydomain.com] (may be forged), pleased to meet you",
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,5,192.168 .116.4:203 7,89.105.9 6.56:25,<, 250-ENHANC EDSTATUSCO DES,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,6,192.168 .116.4:203 7,89.105.9 6.56:25,<, 250-PIPELI NING,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,7,192.168 .116.4:203 7,89.105.9 6.56:25,<, 250-8BITMI ME,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,8,192.168 .116.4:203 7,89.105.9 6.56:25,<, 250-SIZE,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,9,192.168 .116.4:203 7,89.105.9 6.56:25,<, 250-DSN,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,10,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250-ETRN,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,11,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250-DELIV ERBY,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,12,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 HELP,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,13,192.16 8.116.4:20 37,89.105. 96.56:25,* ,419,sendi ng message
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,14,192.16 8.116.4:20 37,89.105. 96.56:25,> ,MAIL FROM:<operator_num_83wgf@h mrc.gov.uk > SIZE=11988,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,15,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@cnsfar nell.com>,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,16,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@city.a c.uk>,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,17,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@excite .co.uk>,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,18,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@elsevi er.com>,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,19,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@bywate rs.co.uk>,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,20,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@bradfo rdcollege. ac.uk>,
2009-04-29T09:47:42.305Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,21,192.16 8.116.4:20 37,89.105. 96.56:25,> ,RCPT TO:<real_local_user@breath e.com>,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,22,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.0 <operator_num_83wgf@hmrc.g ov.uk>... Sender ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,23,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@cnsfarnel l.com>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,24,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@city.ac.u k>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,25,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@excite.co .uk>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,26,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@elsevier. com>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,27,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@bywaters. co.uk>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,28,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@bradfordc ollege.ac. uk>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,29,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.1.5 <real_local_user@breathe.c om>... Recipient ok,
2009-04-29T09:47:42.599Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,30,192.16 8.116.4:20 37,89.105. 96.56:25,> ,DATA,
2009-04-29T09:47:42.607Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,31,192.16 8.116.4:20 37,89.105. 96.56:25,< ,"354 Enter mail, end with ""."" on a line by itself",
2009-04-29T09:47:43.448Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,32,192.16 8.116.4:20 37,89.105. 96.56:25,< ,250 2.0.0 n3T9nhiG006511 Message accepted for delivery,
2009-04-29T09:47:43.448Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,33,192.16 8.116.4:20 37,89.105. 96.56:25,> ,QUIT,
2009-04-29T09:47:43.455Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,34,192.16 8.116.4:20 37,89.105. 96.56:25,< ,221 2.0.0 smtp2.fluidata.co.uk closing connection,
2009-04-29T09:47:43.455Z,M ain SMTP Send Connector,08CB96538CAC4E8E ,35,192.16 8.116.4:20 37,89.105. 96.56:25,- ,,Local
message tracking log:
2009-04-29T09:47:42.130Z,1 23.18.150. 215,,192.1 68.116.4,s pock,08CB9 6538CAC4E8 C;2009-04- 29T09:47:3 8.466Z;0,S POCK\Defau lt SPOCK,SMTP,RECEIVE,419,<00 0801c9c989 $38c6e552$ 0201a8c0@c -ffc4b14a8 d7f4>,,,74 08,1,,,HM Revenue and Customs Notification Tax refund (Internal Revenue Service),operator_num_83wg f@hmrc.gov .uk,operat or_num_83w gf@hmrc.go v.uk,00A:
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@mydom ain.com,,0 ,1,,,,,ope rator_num_ 83wgf@hmrc .gov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@bradf ordcollege .ac.uk,,0, 1,,,,,oper ator_num_8 3wgf@hmrc. gov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@breat he.com,,0, 1,,,,,oper ator_num_8 3wgf@hmrc. gov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@bywat ers.co.uk, ,0,1,,,,,o perator_nu m_83wgf@hm rc.gov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@city. ac.uk,,0,1 ,,,,,opera tor_num_83 wgf@hmrc.g ov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@cnsfa rnell.com, ,0,1,,,,,o perator_nu m_83wgf@hm rc.gov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@elsev ier.com,,0 ,1,,,,,ope rator_num_ 83wgf@hmrc .gov.uk,
2009-04-29T09:47:42.192Z,, spock,,,,, AGENT,RECE IVE,419,,r eal_local_ user@excit e.co.uk,,0 ,1,,,,,ope rator_num_ 83wgf@hmrc .gov.uk,
2009-04-29T09:47:42.268Z,, ,,spock,Qu arantine,, DSN,DSN,42 0,<44a7df5 a-7fdb-4d1 b-a71d-560 aa8754617> ,email_adm in@mydomai n.com,,180 10,1,,,Und eliverable : ,postmaster@mydomain.com,< >,
2009-04-29T09:47:42.322Z,, spock,,spo ck,,,STORE DRIVER,DEL IVER,419,, real_local _user@mydo main.com,, 11988,1,,, ,,operator _num_83wgf @hmrc.gov. uk,2009-04 -29T09:47: 40.813Z
2009-04-29T09:47:42.985Z,, spock,,spo ck,,,STORE DRIVER,DEL IVER,420,< 44a7df5a-7 fdb-4d1b-a 71d-560aa8 754617>,em ail_admin@ mydomain.c om,,18491, 1,,,Undeli verable: ,postmaster@mydomain.com,A dministrat or@mydomai n.com,
2009-04-29T09:47:43.448Z,1 92.168.116 .4,spock,8 9.105.96.5 6,smtp2.fl uidata.co. uk,08CB965 38CAC4E8E, Main SMTP Send Connector,SMTP,SEND,419,<0 00801c9c98 9$38c6e552 $0201a8c0@ c-ffc4b14a 8d7f4>,rea l_local_us er@cnsfarn ell.com;re al_local_u ser@city.a c.uk;real_ local_user @excite.co .uk;real_l ocal_user@ elsevier.c om;real_lo cal_user@b ywaters.co .uk;real_l ocal_user@ bradfordco llege.ac.u k;real_loc al_user@br eathe.com, 250 2.1.5 <real_local_user@cnsfarnel l.com>... Recipient ok;250 2.1.5 <real_local_user@city.ac.u k>... Recipient ok;250 2.1.5 <real_local_user@excite.co .uk>... Recipient ok;250 2.1.5 <real_local_user@elsevier. com>... Recipient ok;250 2.1.5 <real_local_user@bywaters. co.uk>... Recipient ok;250 2.1.5 <real_local_user@bradfordc ollege.ac. uk>... Recipient ok;250 2.1.5 <real_local_user@breathe.c om>... Recipient ok,11984,7,,;;;;;;,HM Revenue and Customs Notification Tax refund (Internal Revenue Service),operator_num_83wg f@hmrc.gov .uk,operat or_num_83w gf@hmrc.go v.uk,2009- 04-29T09:4 7:40.813Z
the spam message header:
Delivery of this message to the following recipients or distribution lists is quarantined:
real_local_user@mydomain.c om
Subject:
-------------------------- ---------- ---------- ---------- ---------- ---------- ----
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: mydomain.local
real_local_user@mydomain.c om
#550 5.2.1 Content Filter agent quarantined this message ##
Original message headers:
thread-index: AcnIr4pOQbUab6mNS6mROwyg1O sA5Q==
Received: from hmrc.gov.uk (123.18.150.215) by spock.mydomain.local (192.168.116.4) with Microsoft SMTP Server id 8.1.358.0; Wed, 29 Apr 2009 10:47:40 +0100
Message-ID: <000801c9c989$38c6e552$020 1a8c0@c-ff c4b14a8d7f 4>
From: "HMRC Tax Refunds On-line" <operator_num_83wgf@hmrc.g ov.uk>
To: <real_local_user@mydomain. com>
BCC: <real_local_user@bradfordc ollege.ac. uk>,
      <real_local_user@breathe.c om>,
      <real_local_user@bywaters. co.uk>,
      <real_local_user@city.ac.u k>,
      <real_local_user@cnsfarnel l.com>,
      <real_local_user@elsevier. com>,
      <real_local_user@excite.co .uk>
Subject: HM Revenue and Customs Notification Tax refund (Internal Revenue Service)
Content-Transfer-Encoding: 7bit
Date: Thu, 30 Apr 2009 04:45:55 -0700
MIME-Version: 1.0
Content-Type: multipart/related;
      boundary="----=_NextPart_0 00_0004_01 C9C94E.8C6 59770";
      type="multipart/alternativ e"
X-Priority: 3
X-MSMail-Priority: Normal
Content-Class: urn:content-classes:messag e
Importance: normal
Priority: normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18049
Return-Path: <operator_num_83wgf@hmrc.g ov.uk>
Received-SPF: None (spock.mydomain.local: operator_num_83wgf@hmrc.go v.uk does not designate permitted sender hosts)
X-TM-AS-Product-Ver: SMEX-8.0.0.4125-5.600.1016 -16610.003
X-TM-AS-Result: Yes-64.271900-4.000000-31
X-TM-AS-User-Approved-Send er: No
X-TM-AS-User-Blocked-Sende r: No
I am experiencing a strange spam issue with my Exchange 2007 server (with the latest service pack and rollups) recently.
My config is:
Exchange 2007 SP1 with latest rollup (x64)
Windows Server 2008 x64
TrendMicro ScanMail (for spam and AV filtering)
I have checked that I am NOT an open relay by telneting to exchange port 25.
Also I have set Accepted Domains in Hub Transport and it is limited to my own domains only.
My problem is:
I am getting outgoing spam from my exchange server on the outgoing SMTP connector the frequency is of this problem is about 3 to 4 spam a day that went thru my outgoing SMTP connector.
Based on what I see from the message tracking tool, I can see that the spam will come thru the incoming SMTP first, destined to one of our real email addresses (as well as a bunch of other non-local email addresses in the CC: field) local to our domain, the spam will then get Quarantined by the content filtering using SCL rating of 7 for our exchange server.
However the spam message will somehow get thru to our outgoing SMTP connector and the message get sent to the non-local recipients in the CC: field
Please find below outgoing and incoming SMTP logs and the relevant part of message tracking log, as well as the header of the spam message itself.
Some notes:
For illustration purpose our domain is mydomain.com (public) and mydomain.local (LAN)
Our exchange mail server is called SPOCK
In these logs I have changed the real user name to real_local_user
Our ISPs SMTP smart host I used for outgoing mail is from fluidata.co.uk
The spammers are spoofing hmrc.gov.gov.uk in this case
Here are the logs:
SMTP receive log:
2009-04-29T09:47:38.466Z,S
2009-04-29T09:47:38.466Z,S
2009-04-29T09:47:38.467Z,S
2009-04-29T09:47:39.036Z,S
2009-04-29T09:47:39.037Z,S
2009-04-29T09:47:39.608Z,S
2009-04-29T09:47:39.608Z,S
2009-04-29T09:47:39.608Z,S
2009-04-29T09:47:40.261Z,S
2009-04-29T09:47:40.264Z,S
2009-04-29T09:47:40.812Z,S
2009-04-29T09:47:40.813Z,S
2009-04-29T09:47:42.130Z,S
2009-04-29T09:47:42.691Z,S
2009-04-29T09:47:42.691Z,S
2009-04-29T09:47:42.692Z,S
SMTP send log:
2009-04-29T09:47:42.269Z,M
2009-04-29T09:47:42.277Z,M
2009-04-29T09:47:42.295Z,M
2009-04-29T09:47:42.295Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.305Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.599Z,M
2009-04-29T09:47:42.607Z,M
2009-04-29T09:47:43.448Z,M
2009-04-29T09:47:43.448Z,M
2009-04-29T09:47:43.455Z,M
2009-04-29T09:47:43.455Z,M
message tracking log:
2009-04-29T09:47:42.130Z,1
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.192Z,,
2009-04-29T09:47:42.268Z,,
2009-04-29T09:47:42.322Z,,
2009-04-29T09:47:42.985Z,,
2009-04-29T09:47:43.448Z,1
the spam message header:
Delivery of this message to the following recipients or distribution lists is quarantined:
real_local_user@mydomain.c
Subject:
--------------------------
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: mydomain.local
real_local_user@mydomain.c
#550 5.2.1 Content Filter agent quarantined this message ##
Original message headers:
thread-index: AcnIr4pOQbUab6mNS6mROwyg1O
Received: from hmrc.gov.uk (123.18.150.215) by spock.mydomain.local (192.168.116.4) with Microsoft SMTP Server id 8.1.358.0; Wed, 29 Apr 2009 10:47:40 +0100
Message-ID: <000801c9c989$38c6e552$020
From: "HMRC Tax Refunds On-line" <operator_num_83wgf@hmrc.g
To: <real_local_user@mydomain.
BCC: <real_local_user@bradfordc
      <real_local_user@breathe.c
      <real_local_user@bywaters.
      <real_local_user@city.ac.u
      <real_local_user@cnsfarnel
      <real_local_user@elsevier.
      <real_local_user@excite.co
Subject: HM Revenue and Customs Notification Tax refund (Internal Revenue Service)
Content-Transfer-Encoding:
Date: Thu, 30 Apr 2009 04:45:55 -0700
MIME-Version: 1.0
Content-Type: multipart/related;
      boundary="----=_NextPart_0
      type="multipart/alternativ
X-Priority: 3
X-MSMail-Priority: Normal
Content-Class: urn:content-classes:messag
Importance: normal
Priority: normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18049
Return-Path: <operator_num_83wgf@hmrc.g
Received-SPF: None (spock.mydomain.local: operator_num_83wgf@hmrc.go
X-TM-AS-Product-Ver: SMEX-8.0.0.4125-5.600.1016
X-TM-AS-Result: Yes-64.271900-4.000000-31
X-TM-AS-User-Approved-Send
X-TM-AS-User-Blocked-Sende
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi Ajermo
Ever since I enabled IP Block List, there have been no further incidents of this kind for 2 days so far.
Thanks for the Technet article. I also found an article about setting up a standalone server - i think my main issue is by using it as standalone I HAVE to set the Default Receive Connector with "Anonymous users" permission otherwise I won't be getting any mail at all:
http://msexchangeteam.com/archive/2006/11/17/431555.aspx
I think I will monitor it over the weekend and see how it goes
Ever since I enabled IP Block List, there have been no further incidents of this kind for 2 days so far.
Thanks for the Technet article. I also found an article about setting up a standalone server - i think my main issue is by using it as standalone I HAVE to set the Default Receive Connector with "Anonymous users" permission otherwise I won't be getting any mail at all:
http://msexchangeteam.com/archive/2006/11/17/431555.aspx
I think I will monitor it over the weekend and see how it goes
ASKER
The issue appears to be on going, however I have now noticed a pattern when these emails were being sent from our server.
In all cases the emails were initially blocked by Content Filtering (Hub Transport -> Anti-Spam) and they were the ones being "Quarantine" when SCL is >= 7 to a mailbox I setup to collect quarantined emails.
May be while the spam was being quarantined, the Exchange server was still trying to forward the mail to other recipients in the CC field? As I have noticed one legitimate email being blocked in this manor over the weekend and our server send out the email via SMTP to the remaining recipients in the CC field. (?)
In all cases the emails were initially blocked by Content Filtering (Hub Transport -> Anti-Spam) and they were the ones being "Quarantine" when SCL is >= 7 to a mailbox I setup to collect quarantined emails.
May be while the spam was being quarantined, the Exchange server was still trying to forward the mail to other recipients in the CC field? As I have noticed one legitimate email being blocked in this manor over the weekend and our server send out the email via SMTP to the remaining recipients in the CC field. (?)
hello i got excatly the same probelm i have sbs exch2007 with sp1 and i am receveing spam from my exchnage unknow user and in the cc i have some users for exch and other from my domain which actualy not create just anyname@mydomain.com then also from another domainname just in cc
and get in the user mail box
any help
i Have NETASQ u70 utm as firewalland antispam but i didn't anable smtp proxy on utm
and get in the user mail box
any help
i Have NETASQ u70 utm as firewalland antispam but i didn't anable smtp proxy on utm
ASKER
Can you suggest a network packet capturing software? The only one I can think of is Ethereal but its operation seems a bit complex.
Also to add some information: My exchange server is just standalone inside our Windows domain, I think I have to buy another Exchange licence from MS to get the Edge Server, is it correct? Also you are right my SMTP is just an open port on our ISA 2006 server, I can't think of a better way to use ISA to filter or check port 25 traffic going internally to Exchange
I have just added zen.spamhaus.org to IP Block List Providers, hoping that will help the situation somewhat.