Solved

Exchange Queue filling with retries "Unable to connect"

Posted on 2013-05-24
4
710 Views
Last Modified: 2013-06-02
We've recently been put on two blacklists so I am looking in the Exchange 2010 queue to see if anything fishy. I see over 100 spam email domains with DNSConnectorDelivery in retry states. All the emails seem to have Undeliverable in subject. One such example below:

Identity: mail1\160283\1565892
Subject: Undeliverable: Ends Today! Get Your Free Gift
Internet Message ID: <70147933-36f8-4039-bf82-dc897bb2975c@ourdomain.net>
From Address: <>
Status: Ready
Size (KB): 10
Message Source Name: DSN
Source IP: 255.255.255.255
SCL: -1
Date Received: 5/22/2013 3:21:52 AM
Expiration Time: 5/27/2013 3:21:52 AM
Last Error:
Queue ID: mail1\160283
Recipients:  EvfPsKGA666@aktifofis.com

The Last error is 451 4.4.0 Primary target IP address responded with: "421 Unable to connect." We are not an open relay and we use Postini to filter our inbound email. I have installed AntiSpam on our Hub Transport and enabled Sender and Recipient Filtering to assist.  
The emails show no sender and no source IP so I don't understand how they are ending up in our queue.

Any ideas?
0
Comment
Question by:ecosys
  • 3
4 Comments
 
LVL 42

Expert Comment

by:Amit
ID: 39195540
Check first internal user. Any user or server hit with a virus attack. Virus can also generate these kind of spam emails. If you have application configured to relay using exchange server. Make sure to use IP based relay. Which means, don't open it for anonymous users. Try this first.
0
 

Author Comment

by:ecosys
ID: 39195606
We only allow IP based relay internally. Also port 25 is restricted to only our Postini servers so all email should be filtered by the time it reaches us. I am not sure if there is an easy way to check for a virus but we have many  servers and users.
0
 

Accepted Solution

by:
ecosys earned 0 total points
ID: 39201414
I've resolved this by installed AntiSpam for Hub Transport. Set up Recipient Filtering to block messages sent to recipients that do not exist in directory. I also blocked emails without sender information, although this may not be necessary.
0
 

Author Closing Comment

by:ecosys
ID: 39214066
I resolved.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
how to add IIS SMTP to handle application/Scanner relays into office 365.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question