Saw something in the Exchange 2010 queue that concerns me. At any given time I see ten to twenty of these messages in retry. I know these are failures scheduled for retry but are there routed messages getting through as well. Is it just backscatter spam? I turned the firewall log on for Server 2008R2 in the hopes of seeing something. Letting it collect for a couple of hours.
The From field
is blank <> and the source ip
(broadcast on the Lan)
Is the source ip correct? Is this backscatter spam or do I possibly have a spam bot on a client somewhere on the lan broadcasting on port 25? My mx record points to postini then to my site and my firewall locks down inbound smtp to only postini's range(s). OWA was opened recently on the firewalls wan interface for a few iphones. There is no Edge Transport Server.
Subject: Undeliverable: Max-Gentleman Enlargement*Pills
Internet Message ID: <f5b9da66-ee93-4440-83cb-a
From Address: <>
Size (KB): 8
Message Source Name: DSN
Source IP: 255.255.255.255
Date Received: 4/6/2012 2:38:24 PM
Expiration Time: 4/8/2012 2:38:24 PM
Last Error: 451 Try again later
Queue ID: msx\178807