Exchange messages being sent from firstname.lastname@example.org
Posted on 2012-09-13
I have been battling a problem for a few days. Exchange 2003 on SBS, email queue filling up with NDR from email@example.com to random email addresses. So, I think the server is an open relay. Check all the settings and run it against mxlookup, it is not an open relay. Then I think it has to be an reverse NDR attack, I checked the settings on Message Delivery and Filter recipients is checked. I check the SMTP connector and can't honestly remember now if Recipient Filters was checked originally, but it is now. I restart exchange and SMTP, still geting emails filling the queue.
I also get emails trying to be delivered locally to domainnameArchive@domainname.com. This seems to be a cut and dry reverse NDR attack, but I can't seem to get the filtering to engage.
Any ideas are appreciated. I travel a lot and may not respond quickly, but will respond.