Spammers bypassing MX records direct to the server
Hi Team,
One of my users is receiving a lot of spam and after analyzing the header i found that the email is getting delivered directly to my server and not through my MX records.
How can i stop spammers from submitting emails direct to my server.
We are running Exchange 2013.
Thanks
Email ServersAntiSpamExchange
Last Comment
Costas Georgiou
8/22/2022 - Mon
Mal Osborne
Huh?
How can you tell from the logs how a spammer determined your IP address? Was the email delivered via an address you have listening on port 25 but not pointed to by an MX record?
Costas Georgiou
ASKER
Correct: All my emails come trough trend micro and for spam emails i can see the email is delivered direct to My IP.
2 Samples below
Spam Email
Received: by Server Name (192.168.75.3) with Microsoft SMTP Server (TLS) id
15.0.1130.7; Wed, 20 Jan 2016 10:47:27 +1100
Received: from 64.203.220.232.dyn-cm-pool-29.pool.hargray.net (64.203.220.232)
by MyServer.local (192.168.75.3) with Microsoft SMTP Server id
15.0.1130.7 via Frontend Transport; Wed, 20 Jan 2016 10:47:24 +1100
Non Spam Email:
Received: from iout2.hes.trendmicro.com (54.219.191.112) by
MyServer.local (192.168.75.3) with Microsoft SMTP Server (TLS) id
15.0.1130.7 via Frontend Transport; Wed, 20 Jan 2016 10:43:38 +1100
John
Do you allow a direct connection to your server for employee and support access? That is, direct instead of VPN?
How can you tell from the logs how a spammer determined your IP address? Was the email delivered via an address you have listening on port 25 but not pointed to by an MX record?