troubleshooting Question

Spam from internal network?

Avatar of Silencer001
Silencer001Flag for Belgium asked on
ExchangeSBSAntiSpam
5 Comments1 Solution385 ViewsLast Modified:
Hi everyone,

A customer of mine keeps getting spam emails from info@theirdomain.net to info@theirdomain.net. They are using Trend Micro's Hosted Email Security for their spam. A policy is active to block *@theirdomain.net to *@theirdomain.net

Normally this would stop the spoofing, but the mails keep getting through. The strange thing is that the mailheaders don't point out that this mail is being filtered by trend micro. Maybe a client is infected with a virus that keeps sending spam?

This is the mailheader from the emails:
 
Received: from 121.96.170.180.BTI.NET.PH (121.96.170.180) by buro.theirdomain.net
 (192.168.0.1) with Microsoft SMTP Server id 8.3.106.1; Wed, 10 Aug 2011
 09:47:56 +0200
Received: from  121.96.170.180 (account <info@theirdomain.net> HELO theirdomain.net)	by
 theirdomain.net (CommuniGate Pro SMTP 5.2.3)	with ESMTPA id 264460314 for
 <info@theirdomain.net>; Wed, 10 Aug 2011 15:48:22 +0800
From: info <info@theirdomain.net>
To: info <info@theirdomain.net>
Date: Wed, 10 Aug 2011 09:48:22 +0200
Subject: Job Proposal
Thread-Topic: Job Proposal
Thread-Index: AcxXMdIw7Kk1fGVnRsaiFRZNzEmdpQ==
Message-ID: <7203926585.5VKXJ9VE285736@ghtpbko.xovsoz.tv>
X-MS-Has-Attach:
X-MS-Exchange-Organization-SenderIdResult: None
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-PRD: theirdomain.net
X-MS-TNEF-Correlator:
received-spf: None (SBS.theirdomain.local: info@theirdomain.net does not designate
 permitted sender hosts)
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0

I hope some of you can shed a light on this.

Kind regards,
Sven
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 5 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 5 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros