Solved

Exchange Mailserver Spam

Posted on 2010-09-15
6
613 Views
Last Modified: 2012-06-27
I need assistance in analyzing an email header. Someone seems to be passing Spam through a customers Exchange server, but can't see how.

Header information below. The IP address of: 70.89.4.109 is the  Exchange Mailserver. The IP of the intruder appears to be: 64.186.141.117

Return-Path: bristollotto03redacted@yahoo.co.jp
Received: from imta19.westchester.pa.mail.comcast.net (LHLO
imta19.westchester.pa.mail.comcast.net) (76.96.62.15) by
sz0165.ev.mail.comcast.net with LMTP; Tue, 14 Sep 2010 12:12:39 +0000 (UTC)
Received: from mailserver2.Inst-Child-Lit.Com ([70.89.4.109])
by imta19.westchester.pa.mail.comcast.net with comcast
id 6cCe1f0202M7bz20KcCefL; Tue, 14 Sep 2010 12:12:40 +0000
X-CAA-SPAM: N00001
X-Authority-Analysis: v=1.1 cv=xQtC0Syy8SjLhPQcxulnFUoy7eUGsAEUo+3gGakOX9w=
c=1 sm=1 p=G0y4NAOPbeQA:10 p=H7zlAlwjME0A:10 p=FlyXWrF0noTvJhcw3_cA:9
a=Dyoqhi_TatcA:10 a=8EU9Q7FnrCoA:10 a=Cfj4BQAnxiAA:10
a=4UKdybQ46eJVya8Ku_wA:7 a=l9BT-LX5JHtfJXMJ0NHU38ZYah4A:4 a=Ft8UYL4EG9YA:10
a=heEvz1zlalEA:10 a=XjuyCbnmBgpgFB-i:21 a=jTmyPk-QPQLX5MgK:21
a=L5inqJBnP8MMvF9QzrwThA==:117
Received: from User ([64.186.141.117]) by mailserver2.Inst-Child-Lit.Com with Microsoft SMTPSVC(6.0.3790.4675);
Mon, 13 Sep 2010 18:42:03 -0400
Reply-To: <bristolsweepstakesredacted@yahoo.co.jp>
From: "BRISTOL LOTTERY"<bristollotto03redacted@yahoo.co.jp>
Subject: AWARD NOTIFICATION.
0
Comment
Question by:frankv_43
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 8

Expert Comment

by:Mkris9
ID: 33683070
have you checked your sever for relay settings ? may be its an open relay ?
0
 

Author Comment

by:frankv_43
ID: 33683151
Yes, the Exchange box has been checked and is NOT open relay.  
0
 
LVL 8

Expert Comment

by:rr1968
ID: 33683454
64.186.141.117 resolves to farm1.myforexvps.com
Also this server is not open relay or at least port 25 is blocked on their side.
Why can't you add this ip in your block list?

0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Accepted Solution

by:
frankv_43 earned 0 total points
ID: 33683563
We did all the obvious stuff, including blocking 64.186.141.117.

Thanks
0
 
LVL 2

Expert Comment

by:joe_h
ID: 33683686
It would really help to see the corresponding log entries from the affected Exchange server. It seems to me that the Exchange box actually is misconfigured as an open relay.
0
 
LVL 6

Expert Comment

by:collins23
ID: 33684069
where is the email destined ?
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Find out what you should include to make the best professional email signature for your organization.
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question