Solved

Exchange sending continuous messages and it's caught in a loop

Posted on 2014-09-30
13
281 Views
Last Modified: 2014-10-02
We are having problems with our client's exchange 2010 server on a 2008 r2.

MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com keeps sending emails to bma_journal@bma.int. This seems to be caught in a loop of some sort. They are being stopped as outgoing mail at our Barracuda mail filter and are being sent at least every minute or so.
 They are being sent by MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@mydomain.local to the @bma.int address. Our mail filter is catching it but i suspect that there is some sort of malware on our exchange server.
I am running Trend Micro scanmail on our stores right now. It's found some malware but the issue is still here.


Thanks

Josef
0
Comment
Question by:Josef Al-Chacar
13 Comments
 
LVL 42

Expert Comment

by:Amit
ID: 40353054
First step I would take to remove anonymous setting relay connectors. Then you can work on virus clean up.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40353220
MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com is a microsoft default MicrosoftExchangeRecipientEmailAddresses and is used by a misconfigured system. No malware.

See this article that explains.  http://ameelabs.org.ua/?p=269
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40354455
Amit: I am unsure how to do this.

Neilsr: If the MicrosoftExchangeRecipientEmailAddresses is MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com that means that the system is misconfigured?

MicrosoftExchangeRecipientEmailAddressPolicyEnabled is set to true. (attched results from Get-OrganizationConfig)

Thanks for the responses

josef
Exchange.JPG
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356063
bma_journal@bma.int

Sounds like you have a Barracuda Mail Archiver in place. Was anything changed with its configuration, or, did this loop occur after changing any settings in the send/receive connectors in Exchange?

I know the Barracuda Mail Archiver has you create a dedicated Send Connector during setup. See here for the documentation.
https://techlib.barracuda.com/BMA/ConfigureMSX20072010EnvelopeJournal
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356078
We used to have the archiver in place but don't anymore. Which is why it's confusing. There is also no bma_journal@bma.int on our exchange server or no journaling rules.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356085
Sounds like you still have some leftover Config then.

Not 100% sure if the Barracuda Mail Filter needs any of the items described in this setup guide though. Wouldn't think it would.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356107
Yeah i've been looking for the config. I just can't find it. It's crazy. I'm digging through exchange and no luck. I'm gonna try a reboot too. It probably won't fix it but it can't hurt.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356113
You might be able to just reverse what that previous document I linked said. Just go back and remove the settings the document tells you to create.

Can't imagine it would affect the Mail Filtering product.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356118
I'll go through in the morning and check every setting listed. Thanks for the link man.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356792
I've gone through all these setting three times and still have found no remnants of the bma_journal address. Only on the mail filter.
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 40356810
This may be why it is trying to send it externally. Because it doesn't exist internally anymore.

Are these messages getting stuck in the queue? Or is the Mail Filter just dropping them?

Sounds like this might be a call to Barracuda.
0
 
LVL 3

Author Closing Comment

by:Josef Al-Chacar
ID: 40357404
You are the freaking man!! It was stuck in the queue on resend. Makes perfect sense! I just removed it and the problem went away.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40358054
Awesome!
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question