Exchange 2003 smtp queue filled with emails mostly from .tw domain
Posted on 2011-02-10
Our SMTP queue is filled with a ton of emails. Most of them end in .tw; for example geo.tw. The queue keeps growing and growing. In SMTP server properties I unchecked "Allow all computers which successfully authenticate to relay, regardless of the list above." I also have "only the list below" selected. After the changes I restarted the smtp service. Still no luck.
I do not see email sent out from postmaster. The sender is some random email address to some random destination email address.
I used network monitor to see where all this smtp traffic is coming from. They were all a bunch of random public ip's; the ip is spoofed.