Missing Email - Exchange 2003
Posted on 2012-08-23
We have a user that reported a missing email from 20 days ago. Our message tracking is set for 14 days so we aren't able to trace it. What we do have are the smpt logs. Looking at the log i found the transmission of the message in question, but it looks to be incomplete. The transmission includes a successful ehlo, mail from, and rcpt to, but I don't see a data command or a quit command, which i suspect is the culprit of either the sending service or exchange. could anyone shed some light on this for me? how could a transmission be missing a quit message. from what i gather, even a reset of a connection should have at least a quit ???
2012-07-31 03:00:26 220.127.116.11 xxxxx.com SMTPSVC1 xxxxxx 192.168.1.200 0 EHLO - +xxxx.com 250 0 325 27 0 SMTP - - - -
2012-07-31 03:00:26 18.104.22.168 xxxxx.com SMTPSVC1 xxxxx 192.168.1.200 0 MAIL - +FROM:<firstname.lastname@example.org> 250 0 45 46 0 SMTP - - - -
2012-07-31 03:00:26 22.214.171.124 xxxxx.com SMTPSVC1 xxxx 192.168.1.200 0 RCPT - +TO:<email@example.com> 250 0 39 57 0 SMTP - - - -