Exchange 2010 Backscatter problem
Posted on 2011-03-15
We are having an issue in Exchange 2010 that i believe is being caused by Backscatter. Recently I have noticed a bunch of messages in the Exchange Queue Viewer that keep trying to resend but are unable to connect. All of these messages are Non Delivery Reports for undeliverable spam email that was sent to our server.
Yesterday afternoon i tried enabling Recipient Validation in exchange. Since turning this feature on we have gone from over 60 messages trying to resend over and over to only 8 after enabling. This seems to have helped the situation, however i am still seeing messages trying to resend.
I found a few articles related to this issue that also recommended completely disabling NDR's all together, or adding another layer of spam detection. Is there any other recommended course of action to resolve this problem? Aside from valid NDR's not being sent, is there any other down side to disabling NDR's? Is there a rule in Exchange we can setup to drop off the NDR's that fail to connect after the first or second try?
Here is alittle background on our current anti-spam setup. Our first layer of anti-spam detection is our Sonicwall firewall which has RBL entries for spamhaus, dnsbl.sorbs, barracudacentral, & spamcop. For the second layer we are using Trend Micro Scan Mail for Exchange. This product doesn't seem to do a good job of cleaning any spam getting through the firewall. I am looking at alternatives as our subscription is up in a few months. Any recommendations on anti-spam products you are having success with are greatly appreciated.
For reference here is a sample of one of the messages currently trying to resend.
Subject: Undeliverable: Loan offer at 3% Interest Rates!!
Internet Message ID: <b925383a-19d1-415d-a701-f6acd8184eae@Qualisauto.com>
From Address: <>
Size (KB): 6
Message Source Name: DSN
Source IP: 255.255.255.255
Date Received: 3/14/2011 8:20:10 PM
Expiration Time: 3/16/2011 8:20:10 PM
Last Error: 450 4.1.1 <firstname.lastname@example.org>: Recipient address rejected: User unknown in local recipient table
Queue ID: qualissrv01\57782