Solved

Exchange 2013 - Check who or what computer sent an email

Posted on 2013-12-11
11
1,100 Views
Last Modified: 2014-01-07
Trying to figure out what user or what computer is sending out spam through our Exchange 2013 server. 99% sure it is internal.

Did this: Get-MessageTrackingLog -ResultSize Unlimited  | Out-GridView

And it doesn't give me much to go on. Is there a better way to do this?
0
Comment
Question by:mvalpreda
  • 6
  • 2
  • 2
  • +1
11 Comments
 
LVL 15

Expert Comment

by:achaldave
Comment Utility
Do you have subject or any more details, you can narrow down results of get-messagetrackinglog output by specifying those details.

Also. do you have any smtp relay connector or relay server, check the headers on one of the spams, it should show the originating server ip/name, it might be one of your web server allowed to relay messages.
0
 
LVL 2

Author Comment

by:mvalpreda
Comment Utility
I have a bunch of bounce messages. That is all. This used to be a lot easier in 2010!
0
 
LVL 2

Author Comment

by:mvalpreda
Comment Utility
It's not spam, it's something from Client Submission Probe. It's flooding my queues.

1) Sender Healthmailbox@domain.local
This is a Probe Mapi message that's Submitted from Store to Mailbox transport Submission service to Hub transport service

2) Sender Healthmailbox@domain.local
Subject : Client Submission Probe

3) Sender : Inbound Proxy Probe
No subject/content
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
Comment Utility
That is Exchange sending those messages.
You wouldn't normally see them in the queues, so something is wrong.
Have you attempted to clean up the databases or mailboxes recently?

If you run this command then you should see these special mailboxes:
Get-Mailbox -Monitoring

Simon.
0
 
LVL 2

Author Comment

by:mvalpreda
Comment Utility
I realized that is Exchange....now. :)

I see three of those "health" mailboxes in there. I have not done anything on this machine. In fact I have not even done updates on it in 2 months!
0
Do email signature updates give you a headache?

Do you feel like you are constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
Comment Utility
CU3 was released last week, I would suggest that you start by updating the server.
There was also a security update for Exchange 2013 released last night.

Simon.
0
 
LVL 15

Expert Comment

by:achaldave
Comment Utility
Check for original-client-ip on message tracking logs.

Since it is internal mailbox and name suggests it is shared mailbox, it narrows down to list of people who has access to the mailbox or has send-as permission on the mailbox.
0
 
LVL 2

Author Comment

by:mvalpreda
Comment Utility
Doing updates now.
0
 
LVL 2

Author Comment

by:mvalpreda
Comment Utility
Nothing in the queues since updates/reboot. I'll keep an eye on it.
0
 
LVL 7

Expert Comment

by:dsnegi_25dec
Comment Utility
this is by design it do the monitoring for databases for every database they hve two system mailboxes 1 for database & another for public folder database
0
 
LVL 2

Author Closing Comment

by:mvalpreda
Comment Utility
I hate when a reboot fixes things......
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
ActiveSync Report 2007 3 16
exchange 2 32
change a Photo on Exchange 3 28
Exchange in VMware 14 48
Check out this infographic on what you need to make a good email signature that will work perfectly for your organization.
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now