Each Recipient of Distribution group receives 10 -20 copy of same mail, but subject is appended with “- Found word(s) free guaranteed in the Text body”
Posted on 2010-08-19
We are facing issue with external users (Email account outside our domain ) getting 10 to 20 copies of same mail (content remains same, but email subject is appended with sentence “- Found word(s) free guaranteed in the Text body", and this sentence is getting appended to subject up to 6 times).
We have hundreds of contacts (external users) added to our exchanges, which is added to a distribution group. This is done for sending some announcements to our external contacts.
Infact this is happening only on following:
1) Issue happens only while sending from one account, we have tried sending mail from different email account and there were no issues
2) Only to distribution group, which has all external contacts (we have distribution group for more than 300 internal users, but this issue is not happening for internal users)
3) If we send mail from same email account to individual contact (members of the same distribution group), there is no issue
In addition, this specific sending email account has a rule created, which says to “forward all incoming mails to a distribution group (internal group for our users) of 30 members”
We did a tracking on exchange server, and could see only one mail being send out, however couldn’t see any mail with different or appended subject.
Further, we have made messagelabs (hosted service) SMTP gateway, both incoming & outgoing mails are routed thru messagelabs. Infact while tracking email with messagelabs we could see all the copies of mails (tracking shows even the mail with appended subject). But nothing is shown with appended subject in our exchange tracking.
Now, we have advised users not to send email to this specific external distribution group. But would appreciate if some could help me to find the solution and root cause.
We did raise the issue with messagelabs, but following are their reply
We have investigated the mailing issue and this appears to be a mailing loop, I have run a search on track and trace for mails from the firstname.lastname@example.org address for the 16th and can see many entries for mails from this address with the same subject line.
Further investigation on our infrastructure shows that all these mails are separate mails sent individually from the sending mail server, and as such can confirm that the sender’s infrastructure seems to have a mail loop occurring on their infrastructure. We have included some of the SMTP logs for the mails below, as you can see the mail hits different servers and towers each time on MessageLabs, indicating these are separate mails.
Results for Log Search (mail ref: 128194737700000101250770001194008)
SMTP Results - Tower 194, Server 8
2010-08-16 08:29:37.698759500 10125077: *** session start ***
2010-08-16 08:29:37.699048500 10125077: Remote IP: 10.10.10.10
2010-08-16 08:29:37.699057500 10125077: Message reference: server-8.tower-194.messagelabs.com!1281947377!10125077!1
2010-08-16 08:29:37.699058500 10125077:
2010-08-16 08:29:37.700281500 10125077: < 220 server-8.tower-194.messagelabs.com ESMTP
2010-08-16 08:29:37.848639500 10125077: > EHLO frontend01.abc.com
2010-08-16 08:29:37.848662500 10125077: < 250-server-8.tower-194.messagelabs.com
2010-08-16 08:29:37.848663500 10125077: 250-STARTTLS
2010-08-16 08:29:37.848664500 10125077: 250-PIPELINING
2010-08-16 08:29:37.848664500 10125077: 250 8BITMIME
2010-08-16 08:29:38.000036500 10125077: > MAIL FROM:<email@example.com>
2010-08-16 08:29:38.006646500 10125077: < 250 OK
2010-08-16 08:29:38.170256500 10125077: > RCPT TO:<bui@ext_domain1.net>
2010-08-16 08:29:38.170266500 10125077: < 250 OK
2010-08-16 08:29:38.170267500 10125077: > RCPT TO:<info@ext_domain2.org>
2010-08-16 08:29:38.170585500 10125077: < 250 OK
2010-08-16 08:29:38.170594500 10125077: > RCPT TO:<hlenthe@ext_domain3.com>
Results for Log Search (mail ref: 128194728800000383701080001195003)
SMTP Results - Tower 195, Server 3
2010-08-16 08:28:08.303910500 38370108: *** session start ***
2010-08-16 08:28:08.304061500 38370108: Remote IP: 10.10.10.10
2010-08-16 08:28:08.304082500 38370108: Message reference: server-3.tower-195.messagelabs.com!1281947288!38370108!1
2010-08-16 08:28:08.304084500 38370108:
2010-08-16 08:28:08.305288500 38370108: < 220 server-3.tower-195.messagelabs.com ESMTP
2010-08-16 08:28:08.486519500 38370108: > EHLO frontend01.abc.com
2010-08-16 08:28:08.486537500 38370108: < 250-server-3.tower-195.messagelabs.com
2010-08-16 08:28:08.486538500 38370108: 250-STARTTLS
2010-08-16 08:28:08.486539500 38370108: 250-PIPELINING
2010-08-16 08:28:08.486540500 38370108: 250 8BITMIME
2010-08-16 08:28:08.654933500 38370108: > MAIL FROM:<firstname.lastname@example.org>
2010-08-16 08:28:08.698722500 38370108: < 250 OK
2010-08-16 08:28:08.861114500 38370108: > RCPT TO:<bui@ext_domain1.net>