Solved

Exchange sending continuous messages and it's caught in a loop

Posted on 2014-09-30
13
287 Views
Last Modified: 2014-10-02
We are having problems with our client's exchange 2010 server on a 2008 r2.

MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com keeps sending emails to bma_journal@bma.int. This seems to be caught in a loop of some sort. They are being stopped as outgoing mail at our Barracuda mail filter and are being sent at least every minute or so.
 They are being sent by MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@mydomain.local to the @bma.int address. Our mail filter is catching it but i suspect that there is some sort of malware on our exchange server.
I am running Trend Micro scanmail on our stores right now. It's found some malware but the issue is still here.


Thanks

Josef
0
Comment
Question by:Josef Al-Chacar
13 Comments
 
LVL 42

Expert Comment

by:Amit
ID: 40353054
First step I would take to remove anonymous setting relay connectors. Then you can work on virus clean up.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40353220
MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com is a microsoft default MicrosoftExchangeRecipientEmailAddresses and is used by a misconfigured system. No malware.

See this article that explains.  http://ameelabs.org.ua/?p=269
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40354455
Amit: I am unsure how to do this.

Neilsr: If the MicrosoftExchangeRecipientEmailAddresses is MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com that means that the system is misconfigured?

MicrosoftExchangeRecipientEmailAddressPolicyEnabled is set to true. (attched results from Get-OrganizationConfig)

Thanks for the responses

josef
Exchange.JPG
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356063
bma_journal@bma.int

Sounds like you have a Barracuda Mail Archiver in place. Was anything changed with its configuration, or, did this loop occur after changing any settings in the send/receive connectors in Exchange?

I know the Barracuda Mail Archiver has you create a dedicated Send Connector during setup. See here for the documentation.
https://techlib.barracuda.com/BMA/ConfigureMSX20072010EnvelopeJournal
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356078
We used to have the archiver in place but don't anymore. Which is why it's confusing. There is also no bma_journal@bma.int on our exchange server or no journaling rules.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356085
Sounds like you still have some leftover Config then.

Not 100% sure if the Barracuda Mail Filter needs any of the items described in this setup guide though. Wouldn't think it would.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356107
Yeah i've been looking for the config. I just can't find it. It's crazy. I'm digging through exchange and no luck. I'm gonna try a reboot too. It probably won't fix it but it can't hurt.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356113
You might be able to just reverse what that previous document I linked said. Just go back and remove the settings the document tells you to create.

Can't imagine it would affect the Mail Filtering product.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356118
I'll go through in the morning and check every setting listed. Thanks for the link man.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356792
I've gone through all these setting three times and still have found no remnants of the bma_journal address. Only on the mail filter.
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 40356810
This may be why it is trying to send it externally. Because it doesn't exist internally anymore.

Are these messages getting stuck in the queue? Or is the Mail Filter just dropping them?

Sounds like this might be a call to Barracuda.
0
 
LVL 3

Author Closing Comment

by:Josef Al-Chacar
ID: 40357404
You are the freaking man!! It was stuck in the queue on resend. Makes perfect sense! I just removed it and the problem went away.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40358054
Awesome!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question