Solved

Exchange sending continuous messages and it's caught in a loop

Posted on 2014-09-30
13
261 Views
Last Modified: 2014-10-02
We are having problems with our client's exchange 2010 server on a 2008 r2.

MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com keeps sending emails to bma_journal@bma.int. This seems to be caught in a loop of some sort. They are being stopped as outgoing mail at our Barracuda mail filter and are being sent at least every minute or so.
 They are being sent by MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@mydomain.local to the @bma.int address. Our mail filter is catching it but i suspect that there is some sort of malware on our exchange server.
I am running Trend Micro scanmail on our stores right now. It's found some malware but the issue is still here.


Thanks

Josef
0
Comment
Question by:Josef Al-Chacar
13 Comments
 
LVL 41

Expert Comment

by:Amit
ID: 40353054
First step I would take to remove anonymous setting relay connectors. Then you can work on virus clean up.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40353220
MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com is a microsoft default MicrosoftExchangeRecipientEmailAddresses and is used by a misconfigured system. No malware.

See this article that explains.  http://ameelabs.org.ua/?p=269
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40354455
Amit: I am unsure how to do this.

Neilsr: If the MicrosoftExchangeRecipientEmailAddresses is MicrosoftExchange329e71ec88ae4615bbc36ab6ce41109e@domain.com that means that the system is misconfigured?

MicrosoftExchangeRecipientEmailAddressPolicyEnabled is set to true. (attched results from Get-OrganizationConfig)

Thanks for the responses

josef
Exchange.JPG
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356063
bma_journal@bma.int

Sounds like you have a Barracuda Mail Archiver in place. Was anything changed with its configuration, or, did this loop occur after changing any settings in the send/receive connectors in Exchange?

I know the Barracuda Mail Archiver has you create a dedicated Send Connector during setup. See here for the documentation.
https://techlib.barracuda.com/BMA/ConfigureMSX20072010EnvelopeJournal
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356078
We used to have the archiver in place but don't anymore. Which is why it's confusing. There is also no bma_journal@bma.int on our exchange server or no journaling rules.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356085
Sounds like you still have some leftover Config then.

Not 100% sure if the Barracuda Mail Filter needs any of the items described in this setup guide though. Wouldn't think it would.
0
Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356107
Yeah i've been looking for the config. I just can't find it. It's crazy. I'm digging through exchange and no luck. I'm gonna try a reboot too. It probably won't fix it but it can't hurt.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40356113
You might be able to just reverse what that previous document I linked said. Just go back and remove the settings the document tells you to create.

Can't imagine it would affect the Mail Filtering product.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356118
I'll go through in the morning and check every setting listed. Thanks for the link man.
0
 
LVL 3

Author Comment

by:Josef Al-Chacar
ID: 40356792
I've gone through all these setting three times and still have found no remnants of the bma_journal address. Only on the mail filter.
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 40356810
This may be why it is trying to send it externally. Because it doesn't exist internally anymore.

Are these messages getting stuck in the queue? Or is the Mail Filter just dropping them?

Sounds like this might be a call to Barracuda.
0
 
LVL 3

Author Closing Comment

by:Josef Al-Chacar
ID: 40357404
You are the freaking man!! It was stuck in the queue on resend. Makes perfect sense! I just removed it and the problem went away.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40358054
Awesome!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now