?
Solved

Exchange 2013 - Check who or what computer sent an email

Posted on 2013-12-11
11
Medium Priority
?
1,172 Views
Last Modified: 2014-01-07
Trying to figure out what user or what computer is sending out spam through our Exchange 2013 server. 99% sure it is internal.

Did this: Get-MessageTrackingLog -ResultSize Unlimited  | Out-GridView

And it doesn't give me much to go on. Is there a better way to do this?
0
Comment
Question by:mvalpreda
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 2
  • 2
  • +1
11 Comments
 
LVL 15

Expert Comment

by:achaldave
ID: 39711741
Do you have subject or any more details, you can narrow down results of get-messagetrackinglog output by specifying those details.

Also. do you have any smtp relay connector or relay server, check the headers on one of the spams, it should show the originating server ip/name, it might be one of your web server allowed to relay messages.
0
 
LVL 2

Author Comment

by:mvalpreda
ID: 39711752
I have a bunch of bounce messages. That is all. This used to be a lot easier in 2010!
0
 
LVL 2

Author Comment

by:mvalpreda
ID: 39711791
It's not spam, it's something from Client Submission Probe. It's flooding my queues.

1) Sender Healthmailbox@domain.local
This is a Probe Mapi message that's Submitted from Store to Mailbox transport Submission service to Hub transport service

2) Sender Healthmailbox@domain.local
Subject : Client Submission Probe

3) Sender : Inbound Proxy Probe
No subject/content
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39711828
That is Exchange sending those messages.
You wouldn't normally see them in the queues, so something is wrong.
Have you attempted to clean up the databases or mailboxes recently?

If you run this command then you should see these special mailboxes:
Get-Mailbox -Monitoring

Simon.
0
 
LVL 2

Author Comment

by:mvalpreda
ID: 39711851
I realized that is Exchange....now. :)

I see three of those "health" mailboxes in there. I have not done anything on this machine. In fact I have not even done updates on it in 2 months!
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 2000 total points
ID: 39711891
CU3 was released last week, I would suggest that you start by updating the server.
There was also a security update for Exchange 2013 released last night.

Simon.
0
 
LVL 15

Expert Comment

by:achaldave
ID: 39711900
Check for original-client-ip on message tracking logs.

Since it is internal mailbox and name suggests it is shared mailbox, it narrows down to list of people who has access to the mailbox or has send-as permission on the mailbox.
0
 
LVL 2

Author Comment

by:mvalpreda
ID: 39711918
Doing updates now.
0
 
LVL 2

Author Comment

by:mvalpreda
ID: 39711967
Nothing in the queues since updates/reboot. I'll keep an eye on it.
0
 
LVL 7

Expert Comment

by:dsnegi_25dec
ID: 39715873
this is by design it do the monitoring for databases for every database they hve two system mailboxes 1 for database & another for public folder database
0
 
LVL 2

Author Closing Comment

by:mvalpreda
ID: 39763584
I hate when a reboot fixes things......
0

Featured Post

Enroll in August's Course of the Month

August's CompTIA IT Fundamentals course includes 19 hours of basic computer principle modules and prepares you for the certification exam. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question