Exchange 2007 NDR (backscatter) spam

I am having problems fighting NDR (backscatter) spam on Exchange 2007 server.
I have been using Exchange Antispam modules for few years now. But last week client started to receive hundreds of NDR (apparently created by my Exchange 2007 server). It is unlikely that is he sending spam.

1. I have tested my SPF records. It all looks OK.
2. I ve tested that it is not a open relay.
3. I have disabled "Allow non delivery reports" on Hub Transport default remote domain.
4. Tried to restart services on Hub transport role server.

NDR spam still arrives as like nothing has changed. Is there anything else i can do?
ivugrinecAsked:
Who is Participating?
 
Alan HardistyCo-OwnerCommented:
Do you receive email directly to your server or are you using a 3rd party smarthost to receive your mail and pass it on to you?

If the latter, then you have to enable Recipient Filtering on your Smarthost otherwise the problem won't go away.

If the former - then turn off the Exchange AV and install a trial of Vamsoft ORF and then the problem will go away (with Recipient Filtering enabled).
0
 
ivugrinecAuthor Commented:
I have Exchange 2007 Hub transport role server published via Microsoft Forefront TMG. So i think it is "directly".

Recipient Filtering is (and was) enabled all this time as is most of the Antispma modules (DNS blocklists, etc).

Is there a Microsoft solution? I have no budget for 3rd party solution.
0
 
ivugrinecAuthor Commented:
Well ORF is preaty cheap. I will consider that as a solution.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

 
Alan HardistyCo-OwnerCommented:
I have never been a fan of the MS Anti-Spam and disable it on all servers I manage as it is too inflexible for my liking.  ORF is a very good and very cheap product and you don't have to renew it if you don't want to - and if you don't renew it, it will continue to work happily.  Should you then decide to upgrade to the latest version, you would have to buy it again.

$239 is a great price and I am sure you will like it and I can help you configure it if you have any questions.

Regarding the receipt of emails 'directly', if your MX record(s) point to your server's IP Address, then you receive email directly.  You can check this on www.mxtoolbox.com
0
 
ivugrinecAuthor Commented:
I receive my email directly.
Do you know if ORF is as good as GFI MailEssentials? Does ORF have a inteligent (bayesian, or statistical or some other mathematical, probability filter?
0
 
Alan HardistyCo-OwnerCommented:
Don't know GFI Mail Essentials.  ORF doesn't use Bayesian or any other type of filtering - it looks primarily at the source of the email and if blacklisted, badly configured, lacking Reverse DNS etc, it will reject it.  It's major tool is Greylisting which temporarily rejects the first connection attempt from a new sender (which kills most spam immediately).  Upon the second send attempt, it will listen more readily to the connection and if the server passes al the other checks, it will let the email through.

Coupled with the Auto-Sender Whitelist, when an internal sender emails someone externally, it will add the Recipient to the Auto-Sender Whitelist and when the external Recipient replies to the internal user, the email goes through far fewer checks and usually just sails straight through.

As a guide, I have received 37 spam emails since January 2011.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.