Solved

Exchange Queue filling with retries "Unable to connect"

Posted on 2013-05-24
4
685 Views
Last Modified: 2013-06-02
We've recently been put on two blacklists so I am looking in the Exchange 2010 queue to see if anything fishy. I see over 100 spam email domains with DNSConnectorDelivery in retry states. All the emails seem to have Undeliverable in subject. One such example below:

Identity: mail1\160283\1565892
Subject: Undeliverable: Ends Today! Get Your Free Gift
Internet Message ID: <70147933-36f8-4039-bf82-dc897bb2975c@ourdomain.net>
From Address: <>
Status: Ready
Size (KB): 10
Message Source Name: DSN
Source IP: 255.255.255.255
SCL: -1
Date Received: 5/22/2013 3:21:52 AM
Expiration Time: 5/27/2013 3:21:52 AM
Last Error:
Queue ID: mail1\160283
Recipients:  EvfPsKGA666@aktifofis.com

The Last error is 451 4.4.0 Primary target IP address responded with: "421 Unable to connect." We are not an open relay and we use Postini to filter our inbound email. I have installed AntiSpam on our Hub Transport and enabled Sender and Recipient Filtering to assist.  
The emails show no sender and no source IP so I don't understand how they are ending up in our queue.

Any ideas?
0
Comment
Question by:ecosys
  • 3
4 Comments
 
LVL 41

Expert Comment

by:Amit
ID: 39195540
Check first internal user. Any user or server hit with a virus attack. Virus can also generate these kind of spam emails. If you have application configured to relay using exchange server. Make sure to use IP based relay. Which means, don't open it for anonymous users. Try this first.
0
 

Author Comment

by:ecosys
ID: 39195606
We only allow IP based relay internally. Also port 25 is restricted to only our Postini servers so all email should be filtered by the time it reaches us. I am not sure if there is an easy way to check for a virus but we have many  servers and users.
0
 

Accepted Solution

by:
ecosys earned 0 total points
ID: 39201414
I've resolved this by installed AntiSpam for Hub Transport. Set up Recipient Filtering to block messages sent to recipients that do not exist in directory. I also blocked emails without sender information, although this may not be necessary.
0
 

Author Closing Comment

by:ecosys
ID: 39214066
I resolved.
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates‚Ķ

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now