Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange sending continuous messages and it's caught in a loop

Posted on 2014-09-30
13
Medium Priority
?
349 Views
Last Modified: 2014-10-02
We are having problems with our client's exchange 2010 server on a 2008 r2.

MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com keeps sending emails to bma_journal@bma.int. This seems to be caught in a loop of some sort. They are being stopped as outgoing mail at our Barracuda mail filter and are being sent at least every minute or so.
 They are being sent by MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@mydomain.local to the @bma.int address. Our mail filter is catching it but i suspect that there is some sort of malware on our exchange server.
I am running Trend Micro scanmail on our stores right now. It's found some malware but the issue is still here.


Thanks

Josef
0
Comment
Question by:Josef Al-Chacar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
13 Comments
 
LVL 44

Expert Comment

by:Amit
ID: 40353054
First step I would take to remove anonymous setting relay connectors. Then you can work on virus clean up.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40353220
MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com is a microsoft default MicrosoftExchangeRecipientEmailAddresses and is used by a misconfigured system. No malware.

See this article that explains.  http://ameelabs.org.ua/?p=269
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40354455
Amit: I am unsure how to do this.

Neilsr: If the MicrosoftExchangeRecipientEmailAddresses is MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com that means that the system is misconfigured?

MicrosoftExchangeRecipientEmailAddressPolicyEnabled is set to true. (attched results from Get-OrganizationConfig)

Thanks for the responses

josef
Exchange.JPG
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356063
bma_journal@bma.int

Sounds like you have a Barracuda Mail Archiver in place. Was anything changed with its configuration, or, did this loop occur after changing any settings in the send/receive connectors in Exchange?

I know the Barracuda Mail Archiver has you create a dedicated Send Connector during setup. See here for the documentation.
https://techlib.barracuda.com/BMA/ConfigureMSX20072010EnvelopeJournal
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356078
We used to have the archiver in place but don't anymore. Which is why it's confusing. There is also no bma_journal@bma.int on our exchange server or no journaling rules.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356085
Sounds like you still have some leftover Config then.

Not 100% sure if the Barracuda Mail Filter needs any of the items described in this setup guide though. Wouldn't think it would.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356107
Yeah i've been looking for the config. I just can't find it. It's crazy. I'm digging through exchange and no luck. I'm gonna try a reboot too. It probably won't fix it but it can't hurt.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356113
You might be able to just reverse what that previous document I linked said. Just go back and remove the settings the document tells you to create.

Can't imagine it would affect the Mail Filtering product.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356118
I'll go through in the morning and check every setting listed. Thanks for the link man.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356792
I've gone through all these setting three times and still have found no remnants of the bma_journal address. Only on the mail filter.
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 2000 total points
ID: 40356810
This may be why it is trying to send it externally. Because it doesn't exist internally anymore.

Are these messages getting stuck in the queue? Or is the Mail Filter just dropping them?

Sounds like this might be a call to Barracuda.
0
 
LVL 3

Author Closing Comment

by:Josef Al-Chacar
ID: 40357404
You are the freaking man!! It was stuck in the queue on resend. Makes perfect sense! I just removed it and the problem went away.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40358054
Awesome!
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
The core idea of this article is to make you acquainted with the best way in which you can export Exchange mailbox to PST format.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question