Found empty sender address mail stuck in queue of Exchange 2k10

This is using MS Exchange server 2010 on MS Windows 2008 R2 server. Recently, in queue viewer, found quite a lot of stuck mail with empty sender address. Please refer to the attached file.

Is this some kind of spamming that want to send via my exchange server? How to stop it? almost all of these stuck mails have error message - 421 4.4.2 Connection dropped due to socket errors.

Thanks in advance.
421---4.4.2-error.bmp
LVL 1
MichaelBalackAsked:
Who is Participating?

[Webinar] Streamline your web hosting managementRegister Today

x
 
Sudhir BidyeConnect With a Mentor Commented:
1) Check if your server is open for relay, if yes then below article can be helpful to fix it.

alanhardisty.wordpress.com/2010/07/12/how-to-close-an-open-relay-in-exchange-2007-2010/

https://exchangemaster.wordpress.com/2013/03/08/checking-for-open-relay-in-exchange-20072010/

2) Run antivirus/antimalware scan on all the user workstation and make sure none of the user accounts are compromised.
0
 
Miguel Angel Perez MuñozCommented:
This appears to be NDR, you may be flooded to inexistent email address and this generates NDR to inexistent domains. This causes your server couldn´t reach to this domains and emails stucks on queue. After 2 days will be remove automatically.
0
 
Gareth GudgerCommented:
These are just Non-Delivery Reports (NDRs) coming back. Could be a result of an NDR backscatter attack.

Articles on Backscatter.
http://technet.microsoft.com/en-us/library/dn499795(v=exchg.150).aspx
http://www.sophos.com/en-us/support/knowledgebase/37088.aspx
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

 
MichaelBalackAuthor Commented:
Hi Sudhir,

Ok, will do it ...
0
 
MichaelBalackAuthor Commented:
I've requested that this question be closed as follows:

Accepted answer: 0 points for MichaelBalack's comment #a40528793

for the following reason:

ok
0
 
Gareth GudgerCommented:
Did you mean to close it that way Michael?
0
 
MichaelBalackAuthor Commented:
yes
0
 
MichaelBalackAuthor Commented:
Hi Sudhir,

Exchange server is not open relay. However, found few PC were infected by malware/virus that broadcast emails to some invalid recipients, thus jam up the mail queue. After getting rid of the malware/virus, no more stuck mail with sender address "empty".
0
All Courses

From novice to tech pro — start learning today.