ComexIT
asked on
Exchange 2003 Sending Spam and IP Blocked
Hi,
I have a issue with a Exchange 2003 server, for the last 2 x days it keeps getting black listed by spamhaus as something is sending spam out, we have checked Anti Virus and all seems ok, any ideas where to start ?
Regards
I have a issue with a Exchange 2003 server, for the last 2 x days it keeps getting black listed by spamhaus as something is sending spam out, we have checked Anti Virus and all seems ok, any ideas where to start ?
Regards
First - are you sure that it is Exchange?
If you look in the queues you will see messages hanging around if the server is being abused, because spammer's lists are not very clean.
If the queues are clean, then the source isn't Exchange.
The next step is to simply block SMTP traffic on the firewall except from the Exchange server. Turn on logging and wait. A compromised workstation will soon appear on the logs and can be found and removed.
If you do have messages in the queues on the Exchange server, it is unlikely to be malware, just a compromised account being used to send out spam.
Simon.
If you look in the queues you will see messages hanging around if the server is being abused, because spammer's lists are not very clean.
If the queues are clean, then the source isn't Exchange.
The next step is to simply block SMTP traffic on the firewall except from the Exchange server. Turn on logging and wait. A compromised workstation will soon appear on the logs and can be found and removed.
If you do have messages in the queues on the Exchange server, it is unlikely to be malware, just a compromised account being used to send out spam.
Simon.
ASKER
Thanks Simon, do you have a list of steps for me to check etc ?
Thanks
Thanks
Try reading my article - link above.
Alan
Alan
ASKER
Thanks Alan,
I think its the ndr version as it shows from postmaster@domain etc, I have applied the filter etc, Do i need to clear the ques ?
I think its the ndr version as it shows from postmaster@domain etc, I have applied the filter etc, Do i need to clear the ques ?
You should do - it will be NDR's going back to invalid addresses, and you don't want to hit any more blacklists sites and get blacklisted.
Are you on Backscatterer.org?
Alan
Are you on Backscatterer.org?
Alan
ASKER
it says not listed but was before etc
Good - let's hope you stay that way.
Have you resolved the Recipient Filtering yet so it doesn't happen again?
Alan
Have you resolved the Recipient Filtering yet so it doesn't happen again?
Alan
ASKER
yes i have enabled the receip filter etc so that should now be ok, why does it happen .... it's a real pain, we thought it was a pc in network etc
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
https://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html
Any questions, please ask.
Alan