Solved

Blacklisted

Posted on 2013-12-09
5
325 Views
Last Modified: 2013-12-09
We are being blacklisted by 9 different blacklist companies according to mxtoolbox.  They include; Barracuda, CBL, Choon, ivmSIP, LASHBACK, NIXSPAM, SPAMCOP, Spamhaus Zen, UCEPROTECTL1.  Not long after I discovered the problem this morning I had a user call and say their computer is basically under attack.  I have shut down the computer.  What is the best way for me to verify that it was this computer causing the issue?
0
Comment
Question by:PDIS
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 1

Expert Comment

by:Trancebolt
ID: 39706259
Very difficult... I have had this problem with a few domains/ips...

Its either someone in house doing mass mailers or your outbound security is low so people are spoofing your name.

Barracuda is often one that blocks me...
0
 
LVL 13

Expert Comment

by:Alexios
ID: 39706278
Hello
It is better to remove the HD, add it as a secondary drive to another PC and scan it with updated antivirus and antimalware software.
Some examples
http://www.microsoft.com/security_essentials/
http://www.malwarebytes.org/ 

Write down all possible threats that these programs will find and search them to a virus database. In their decription you will if any of them is causing spamming
0
 
LVL 1

Expert Comment

by:Trancebolt
ID: 39706282
VEry sound advice, but in my experience nothing  clears bugs out except reformatting and setting up from scratch =D
0
 

Author Comment

by:PDIS
ID: 39706290
I will reformat the computer before I put it back in use.  I'm just trying to verify that this computer is the culprit for us being blacklisted
0
 
LVL 19

Accepted Solution

by:
xterm earned 500 total points
ID: 39706328
If you have multiple PCs on a LAN that is using NAT behind one common gateway, then all your outbound emails will appear to originate from a single IP address and there is no way of knowing if the infected machine is the culprit.  Obviously, if the machine has a public static IP, then that will be the IP in the DNSBL listing, but I'm guessing that's not the case for you.

The best thing you can do is put an internal ACL on your switches/routers that denies all outbound SMTP (port 25/tcp) to any IP except for your actual Exchange/SMTP server(s).  This forces systems to relay instead of doing direct-to-MX, and then you can deploy controls on Exchange itself to limit outbound volume.
0

Featured Post

[Live Webinar] The Cloud Skills Gap

As Cloud technologies come of age, business leaders grapple with the impact it has on their team's skills and the gap associated with the use of a cloud platform.

Join experts from 451 Research and Concerto Cloud Services on July 27th where we will examine fact and fiction.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question