[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 172
  • Last Modified:

Found empty sender address mail stuck in queue of Exchange 2k10

This is using MS Exchange server 2010 on MS Windows 2008 R2 server. Recently, in queue viewer, found quite a lot of stuck mail with empty sender address. Please refer to the attached file.

Is this some kind of spamming that want to send via my exchange server? How to stop it? almost all of these stuck mails have error message - 421 4.4.2 Connection dropped due to socket errors.

Thanks in advance.
421---4.4.2-error.bmp
0
MichaelBalack
Asked:
MichaelBalack
1 Solution
 
Miguel Angel Perez MuñozCommented:
This appears to be NDR, you may be flooded to inexistent email address and this generates NDR to inexistent domains. This causes your server couldn´t reach to this domains and emails stucks on queue. After 2 days will be remove automatically.
0
 
Gareth GudgerCommented:
These are just Non-Delivery Reports (NDRs) coming back. Could be a result of an NDR backscatter attack.

Articles on Backscatter.
http://technet.microsoft.com/en-us/library/dn499795(v=exchg.150).aspx
http://www.sophos.com/en-us/support/knowledgebase/37088.aspx
0
 
Sudhir BidyeCommented:
1) Check if your server is open for relay, if yes then below article can be helpful to fix it.

alanhardisty.wordpress.com/2010/07/12/how-to-close-an-open-relay-in-exchange-2007-2010/

https://exchangemaster.wordpress.com/2013/03/08/checking-for-open-relay-in-exchange-20072010/

2) Run antivirus/antimalware scan on all the user workstation and make sure none of the user accounts are compromised.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
MichaelBalackAuthor Commented:
Hi Sudhir,

Ok, will do it ...
0
 
MichaelBalackAuthor Commented:
I've requested that this question be closed as follows:

Accepted answer: 0 points for MichaelBalack's comment #a40528793

for the following reason:

ok
0
 
Gareth GudgerCommented:
Did you mean to close it that way Michael?
0
 
MichaelBalackAuthor Commented:
yes
0
 
MichaelBalackAuthor Commented:
Hi Sudhir,

Exchange server is not open relay. However, found few PC were infected by malware/virus that broadcast emails to some invalid recipients, thus jam up the mail queue. After getting rid of the malware/virus, no more stuck mail with sender address "empty".
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now