pgoldwasser
asked on
SPAM email being sent through our Exchange server
We are finding each night that someone is sending emails through our Exchange server from outside. This is Exchange 2010 and I am certain that we have the open realy turned off. In the Receive connector we do NOT have externally secured checked off on the Authentication tab. I believe that is how you turn on or off an open realy. I also have set on the network tab to only receive email from our internal networks. However these emails are originating from ip addresses outside of our networks. We have a Barracuda SPAM filtering gateway so all the spam is being stopped there, however, we want to find a way to say that only email FROM our organization is permitted on the Exchange server. Last night the emails were all coming FROM test@live.com. The night before they were coming from e-mails@yahoo.com. Only email from tbj.org (our domain) should be permitted to leave our exchange server.
Can anyone help me to set this up?
Thanks!
Can anyone help me to set this up?
Thanks!
Hi,
Just did a short test, and your server is not allowing external relays either to or from live.com or yahoo.com, so it must be internal. (i have removed the ip and your servername)
Connecting to
220 ESMTP [889 ms]
EHLO smtp.live.com
250- Hello smtp.live.com [65.55.172.254], pleased to meet you
250-SIZE 100000000
250-PIPELINING
250-8BITMIME
250 HELP [686 ms]
MAIL FROM: <me@live.com>
250 Sender <me@live.com> OK [686 ms]
RCPT TO: <me@yahoo.com>
550 relay not permitted [718 ms]
Cheers
Leon
Just did a short test, and your server is not allowing external relays either to or from live.com or yahoo.com, so it must be internal. (i have removed the ip and your servername)
Connecting to
220 ESMTP [889 ms]
EHLO smtp.live.com
250- Hello smtp.live.com [65.55.172.254], pleased to meet you
250-SIZE 100000000
250-PIPELINING
250-8BITMIME
250 HELP [686 ms]
MAIL FROM: <me@live.com>
250 Sender <me@live.com> OK [686 ms]
RCPT TO: <me@yahoo.com>
550 relay not permitted [718 ms]
Cheers
Leon
ASKER
No 1708 in my event logs. I had thought it might be internal from the start, but when the emails would hit the server the source ip would show as outside ipaddresses. I could find no evidence of internal ip addresses in any log that I look at.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Make sure your server is patched.
Change pc passwords.
Update and run antivirus and malware checks on internal machines to be sure.
Change pc passwords.
Update and run antivirus and malware checks on internal machines to be sure.
Check your Event logs for ID 1708 and see if a user is hitting the exchange constantly. This may give you a clue.
Check tips:
https://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn%27t-send.html