Link to home
Start Free TrialLog in
Avatar of brandonrainbolt
brandonrainbolt

asked on

Need help troubleshooting spam sent from my server

I've just noticed that over the last few days, my exchange server has recorded a bunch of NDR's in the event log. It looks like my server is being used to spam, and my IP is starting to show up on a few blacklists. I'm not sure what the source of the trouble is, and I could use some assistance in tracking this down.

I haven't seen any suspicious activity for about a day, and I've just now enabled message tracking on my server, so (as far as I know) I can't use the message tracking center for any of these messages.

I've run some web-based tests to confirm that I'm not an open relay.

Any suggestions for locating the source of this?
ASKER CERTIFIED SOLUTION
Avatar of Exchange_Geek
Exchange_Geek
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of brandonrainbolt
brandonrainbolt

ASKER

Thanks for the reply. Any suggestions for getting information on the messages that were sent? I'd really like to know if they originated from a particular user or ip address. Anything along those line that I might use to track down the source of the issue.
There is only two ways to track such emails -

1) Using Message Tracking logs
2) Using SMTP VS logs (NCSA).

Check for SMTP virtual Server setting - and see if there is any logging enabled on it.

You'll find this at Server -> protocol -> SMTP -> Default SMTP VS -> properties

Regards,
Exchange_Geek
thanks