Found empty sender address mail stuck in queue of Exchange 2k10

This is using MS Exchange server 2010 on MS Windows 2008 R2 server. Recently, in queue viewer, found quite a lot of stuck mail with empty sender address. Please refer to the attached file.

Is this some kind of spamming that want to send via my exchange server? How to stop it? almost all of these stuck mails have error message - 421 4.4.2 Connection dropped due to socket errors.

Thanks in advance.
421---4.4.2-error.bmp
LVL 1
MichaelBalackAsked:
Who is Participating?
 
Sudhir BidyeCommented:
1) Check if your server is open for relay, if yes then below article can be helpful to fix it.

alanhardisty.wordpress.com/2010/07/12/how-to-close-an-open-relay-in-exchange-2007-2010/

https://exchangemaster.wordpress.com/2013/03/08/checking-for-open-relay-in-exchange-20072010/

2) Run antivirus/antimalware scan on all the user workstation and make sure none of the user accounts are compromised.
0
 
Miguel Angel Perez MuñozCommented:
This appears to be NDR, you may be flooded to inexistent email address and this generates NDR to inexistent domains. This causes your server couldn´t reach to this domains and emails stucks on queue. After 2 days will be remove automatically.
0
 
Gareth GudgerCommented:
These are just Non-Delivery Reports (NDRs) coming back. Could be a result of an NDR backscatter attack.

Articles on Backscatter.
http://technet.microsoft.com/en-us/library/dn499795(v=exchg.150).aspx
http://www.sophos.com/en-us/support/knowledgebase/37088.aspx
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 
MichaelBalackAuthor Commented:
Hi Sudhir,

Ok, will do it ...
0
 
MichaelBalackAuthor Commented:
I've requested that this question be closed as follows:

Accepted answer: 0 points for MichaelBalack's comment #a40528793

for the following reason:

ok
0
 
Gareth GudgerCommented:
Did you mean to close it that way Michael?
0
 
MichaelBalackAuthor Commented:
yes
0
 
MichaelBalackAuthor Commented:
Hi Sudhir,

Exchange server is not open relay. However, found few PC were infected by malware/virus that broadcast emails to some invalid recipients, thus jam up the mail queue. After getting rid of the malware/virus, no more stuck mail with sender address "empty".
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.