• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 634
  • Last Modified:

Exchange Mailserver Spam

I need assistance in analyzing an email header. Someone seems to be passing Spam through a customers Exchange server, but can't see how.

Header information below. The IP address of: is the  Exchange Mailserver. The IP of the intruder appears to be:

Return-Path: bristollotto03redacted@yahoo.co.jp
Received: from imta19.westchester.pa.mail.comcast.net (LHLO
imta19.westchester.pa.mail.comcast.net) ( by
sz0165.ev.mail.comcast.net with LMTP; Tue, 14 Sep 2010 12:12:39 +0000 (UTC)
Received: from mailserver2.Inst-Child-Lit.Com ([])
by imta19.westchester.pa.mail.comcast.net with comcast
id 6cCe1f0202M7bz20KcCefL; Tue, 14 Sep 2010 12:12:40 +0000
X-CAA-SPAM: N00001
X-Authority-Analysis: v=1.1 cv=xQtC0Syy8SjLhPQcxulnFUoy7eUGsAEUo+3gGakOX9w=
c=1 sm=1 p=G0y4NAOPbeQA:10 p=H7zlAlwjME0A:10 p=FlyXWrF0noTvJhcw3_cA:9
a=Dyoqhi_TatcA:10 a=8EU9Q7FnrCoA:10 a=Cfj4BQAnxiAA:10
a=4UKdybQ46eJVya8Ku_wA:7 a=l9BT-LX5JHtfJXMJ0NHU38ZYah4A:4 a=Ft8UYL4EG9YA:10
a=heEvz1zlalEA:10 a=XjuyCbnmBgpgFB-i:21 a=jTmyPk-QPQLX5MgK:21
Received: from User ([]) by mailserver2.Inst-Child-Lit.Com with Microsoft SMTPSVC(6.0.3790.4675);
Mon, 13 Sep 2010 18:42:03 -0400
Reply-To: <bristolsweepstakesredacted@yahoo.co.jp>
From: "BRISTOL LOTTERY"<bristollotto03redacted@yahoo.co.jp>
1 Solution
have you checked your sever for relay settings ? may be its an open relay ?
frankv_43Author Commented:
Yes, the Exchange box has been checked and is NOT open relay.  
rr1968Commented: resolves to farm1.myforexvps.com
Also this server is not open relay or at least port 25 is blocked on their side.
Why can't you add this ip in your block list?

Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

frankv_43Author Commented:
We did all the obvious stuff, including blocking

It would really help to see the corresponding log entries from the affected Exchange server. It seems to me that the Exchange box actually is misconfigured as an open relay.
where is the email destined ?
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now