Solved

SmallBussines SMTP connector large queue with postmaster messages

Posted on 2013-11-06
5
380 Views
Last Modified: 2013-11-06
spammer was authenticating with a hacked username against the Small Business Server computer as part of an operation to relay SMTP e-mail, causing an eventid 1708.
Changed account password already, no more emails from "something@something.com" coming out of our exchange.

but now on the "smallbusiness smtp connector queue there are thousands of messages from the postmaster@mydomain.com and it is not stopping, or at least is has been queuing for hours and submitting emails to the email that the spam was sending at.

Another detail is that we have a Mcafee offsite proxy where all our outbound emails go thru. They close the door of our affected ip address until we can tell them that we fix our problem.

I would like to stop the messages from the postmaster and clean the queues.

Thanks
0
Comment
Question by:75carlos
  • 3
  • 2
5 Comments
 
LVL 15

Accepted Solution

by:
Perarduaadastra earned 500 total points
ID: 39626688
This is a common problem that has been addressed several times on EE.

The venerable expert alanhardisty has covered it here:

http://alanhardisty.wordpress.com/2010/02/11/why-are-my-outbound-queues-filling-up-with-mail-that-we-didnt-send/

... and Microsoft addresses the question here:

http://support.microsoft.com/kb/909005

These links should get you out of trouble.
0
 

Author Comment

by:75carlos
ID: 39626981
I'm done with the Authenticated Relay Attach securing process.
At one moment I saw like 60,000 messages on the queue so it will take aawhile to purge everything. I'm using the line command application aqadmcli.exe to speed up the process.

Two things I notice, the messages (Delivery status notification delay and failure)  from "postmaster" are still showing up...maybe are old and still popping up in the queue.....

the messages from the relay email account "membershipsrewards@membershipsrewards.com are still showing up in the SMTP connector but are old one...not sure when it going to end
0
 
LVL 15

Expert Comment

by:Perarduaadastra
ID: 39627002
If you look at Step 3 in the Microsoft KB, it explains that cleaning up the queues can be a lengthy process. If you have 60,000+ messages to get rid of then lengthy is probably an apt description...

Note that it may take some time before the total number of messages to be deleted becomes available.
0
 

Author Comment

by:75carlos
ID: 39627090
I've been turning on the computer and testing, everything up to now is fine but slow.
I'm cleaning by chunks , when it get to 4000 or 5000 I ran aqadmcli.exe using the delmsg flags=all since there is not user activity yet.
0
 
LVL 15

Expert Comment

by:Perarduaadastra
ID: 39627797
A way of speeding up the removal of messages is to stop the SMTP service and rename the Queue folder to something else, for example Badqueue. Then start the SMTP service again; this will generate a new Queue folder that will be empty. You can then delete the contents of the old renamed Queue folder (Badqueue in the example I gave) at your leisure.
Be very sure, however, that there is nothing important in that folder before deleting everything!

I've recently dealt with just such a situation, and it took about ten minutes for 80,000+ files to be deleted from the old renamed Queue folder, which is rather quicker than multiple passes with the aqadmcli utility.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to install USMT 11 86
Lenovo M90 + e-mail + browser? 11 30
Is there a way to adjust the order of the filters / labels in gmail? 6 24
What is CEO Fraud? 8 68
Are you having trouble connecting or getting your iPhone / Samsung device(s) to sync with Microsoft Exchange Server?   What have you tried?   What haven't you tried?
Email signatures have numerous marketing benefits. Here are 8 top reasons to turn your email signature into a marketing channel.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now