?
Solved

Exchange Server 2003 relaying

Posted on 2011-03-22
5
Medium Priority
?
187 Views
Last Modified: 2012-05-11
Hello,

One of our Exchange Server 2003 servers was relayed off of today.  Our ISP saw the traffic and blocked all outgoing from our IP address.  they can quickly turn it on, but I am concerned that the probel is still going on.  My firewall shows perhaps a couple of hundred connections to different IP addresses on ports 25 and another port whidch our ISp had designated using.

0
Comment
Question by:SRC-S1
5 Comments
 
LVL 10

Accepted Solution

by:
Hutch_77 earned 1000 total points
ID: 35195526
Turn relaying off on the exchang eserver before you are blacklisted.. or if you need it set it to authenticate or limit it to specific IP's
0
 

Expert Comment

by:acymcsc
ID: 35195789
You should probably look at the source ip address from which the traffic is coming from.  The block those not authorized to send smtp traffic.
0
 
LVL 10

Expert Comment

by:Muzafar Momin
ID: 35196454
use exchange mail/spam solution(baracoda, ironport.. etc) to avoid such issues
0
 
LVL 17

Expert Comment

by:Viral Rathod
ID: 35197018
1) You need to first check if your server is open realy or not by going  to "http://www.mxtoolbox.com/diagnostic.aspx"

2) Refer follwing article to help Reducing Spam Mails
 
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2527-How-to-prevent-Spoofed-Emails-in-Exchange-2003.html
0
 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 1000 total points
ID: 35197040
Please have a read of my article and see if you are an Authenticated relay:

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html

If you are, you need to figure out which account(s) are being abused and change the password for that account, then restart the SMTP Service and tighten up your security.

My blogs have useful information for you if that is the case:

http://alanhardisty.wordpress.com/2010/09/28/increase-in-frequency-of-security-alerts-on-servers-from-hackers-trying-brute-force-password-programs/

http://alanhardisty.wordpress.com/2010/12/01/increase-in-hacker-attempts-on-windows-exchange-servers-one-way-to-slow-them-down/
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As much as Microsoft wants to kill off PST file support, just as they tried to do with public folders, there are still times when it is useful or downright necessary to export Exchange mailboxes to PST files. Thankfully, it is still possible to e…
If you have come across a situation where you need to find some EDB mailbox recovery techniques, then here you will find the same. In this article, we will take you through three techniques using which you will be able to perform EDB recovery. You …
how to add IIS SMTP to handle application/Scanner relays into office 365.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question