Solved

Exchange sending continuous messages and it's caught in a loop

Posted on 2014-09-30
13
295 Views
Last Modified: 2014-10-02
We are having problems with our client's exchange 2010 server on a 2008 r2.

MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com keeps sending emails to bma_journal@bma.int. This seems to be caught in a loop of some sort. They are being stopped as outgoing mail at our Barracuda mail filter and are being sent at least every minute or so.
 They are being sent by MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@mydomain.local to the @bma.int address. Our mail filter is catching it but i suspect that there is some sort of malware on our exchange server.
I am running Trend Micro scanmail on our stores right now. It's found some malware but the issue is still here.


Thanks

Josef
0
Comment
Question by:Josef Al-Chacar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
13 Comments
 
LVL 43

Expert Comment

by:Amit
ID: 40353054
First step I would take to remove anonymous setting relay connectors. Then you can work on virus clean up.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40353220
MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com is a microsoft default MicrosoftExchangeRecipientEmailAddresses and is used by a misconfigured system. No malware.

See this article that explains.  http://ameelabs.org.ua/?p=269
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40354455
Amit: I am unsure how to do this.

Neilsr: If the MicrosoftExchangeRecipientEmailAddresses is MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com that means that the system is misconfigured?

MicrosoftExchangeRecipientEmailAddressPolicyEnabled is set to true. (attched results from Get-OrganizationConfig)

Thanks for the responses

josef
Exchange.JPG
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356063
bma_journal@bma.int

Sounds like you have a Barracuda Mail Archiver in place. Was anything changed with its configuration, or, did this loop occur after changing any settings in the send/receive connectors in Exchange?

I know the Barracuda Mail Archiver has you create a dedicated Send Connector during setup. See here for the documentation.
https://techlib.barracuda.com/BMA/ConfigureMSX20072010EnvelopeJournal
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356078
We used to have the archiver in place but don't anymore. Which is why it's confusing. There is also no bma_journal@bma.int on our exchange server or no journaling rules.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356085
Sounds like you still have some leftover Config then.

Not 100% sure if the Barracuda Mail Filter needs any of the items described in this setup guide though. Wouldn't think it would.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356107
Yeah i've been looking for the config. I just can't find it. It's crazy. I'm digging through exchange and no luck. I'm gonna try a reboot too. It probably won't fix it but it can't hurt.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356113
You might be able to just reverse what that previous document I linked said. Just go back and remove the settings the document tells you to create.

Can't imagine it would affect the Mail Filtering product.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356118
I'll go through in the morning and check every setting listed. Thanks for the link man.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356792
I've gone through all these setting three times and still have found no remnants of the bma_journal address. Only on the mail filter.
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 40356810
This may be why it is trying to send it externally. Because it doesn't exist internally anymore.

Are these messages getting stuck in the queue? Or is the Mail Filter just dropping them?

Sounds like this might be a call to Barracuda.
0
 
LVL 3

Author Closing Comment

by:Josef Al-Chacar
ID: 40357404
You are the freaking man!! It was stuck in the queue on resend. Makes perfect sense! I just removed it and the problem went away.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40358054
Awesome!
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

An article on effective troubleshooting
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question