Solved

Found empty sender address mail stuck in queue of Exchange 2k10

Posted on 2014-12-30
9
125 Views
Last Modified: 2015-01-24
This is using MS Exchange server 2010 on MS Windows 2008 R2 server. Recently, in queue viewer, found quite a lot of stuck mail with empty sender address. Please refer to the attached file.

Is this some kind of spamming that want to send via my exchange server? How to stop it? almost all of these stuck mails have error message - 421 4.4.2 Connection dropped due to socket errors.

Thanks in advance.
421---4.4.2-error.bmp
0
Comment
Question by:MichaelBalack
9 Comments
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 40523844
This appears to be NDR, you may be flooded to inexistent email address and this generates NDR to inexistent domains. This causes your server couldn´t reach to this domains and emails stucks on queue. After 2 days will be remove automatically.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40523858
These are just Non-Delivery Reports (NDRs) coming back. Could be a result of an NDR backscatter attack.

Articles on Backscatter.
http://technet.microsoft.com/en-us/library/dn499795(v=exchg.150).aspx
http://www.sophos.com/en-us/support/knowledgebase/37088.aspx
0
 
LVL 3

Accepted Solution

by:
Sudhir Bidye earned 500 total points
ID: 40526514
1) Check if your server is open for relay, if yes then below article can be helpful to fix it.

alanhardisty.wordpress.com/2010/07/12/how-to-close-an-open-relay-in-exchange-2007-2010/

https://exchangemaster.wordpress.com/2013/03/08/checking-for-open-relay-in-exchange-20072010/

2) Run antivirus/antimalware scan on all the user workstation and make sure none of the user accounts are compromised.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Author Comment

by:MichaelBalack
ID: 40528793
Hi Sudhir,

Ok, will do it ...
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40543215
I've requested that this question be closed as follows:

Accepted answer: 0 points for MichaelBalack's comment #a40528793

for the following reason:

ok
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40543216
Did you mean to close it that way Michael?
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40550471
yes
0
 
LVL 1

Author Closing Comment

by:MichaelBalack
ID: 40568246
Hi Sudhir,

Exchange server is not open relay. However, found few PC were infected by malware/virus that broadcast emails to some invalid recipients, thus jam up the mail queue. After getting rid of the malware/virus, no more stuck mail with sender address "empty".
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
In-place Upgrading Dirsync to Azure AD Connect
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question