Avatar of Costas Georgiou
Costas Georgiou
Flag for Australia asked on

Spammers bypassing MX records direct to the server

Hi Team,
    One of my users is receiving a lot of spam and after analyzing the header i found that the email is getting delivered directly to my server and not through my MX records.

How can i stop spammers from submitting emails direct to my server.

We are running Exchange 2013.
Thanks
Email ServersAntiSpamExchange

Avatar of undefined
Last Comment
Costas Georgiou

8/22/2022 - Mon
Mal Osborne

Huh?

How can you tell from the logs how a spammer determined your IP address? Was the email delivered via an address you have listening on port 25 but not pointed to by an MX record?
Costas Georgiou

ASKER
Correct: All my emails come trough trend micro and for spam emails i can see the email is delivered direct to My IP.

2 Samples below

Spam Email
Received:  by Server Name (192.168.75.3) with Microsoft SMTP Server (TLS) id
 15.0.1130.7; Wed, 20 Jan 2016 10:47:27 +1100
Received: from 64.203.220.232.dyn-cm-pool-29.pool.hargray.net (64.203.220.232)
 by MyServer.local (192.168.75.3) with Microsoft SMTP Server id
 15.0.1130.7 via Frontend Transport; Wed, 20 Jan 2016 10:47:24 +1100

Non Spam Email:
Received: from iout2.hes.trendmicro.com (54.219.191.112) by
 MyServer.local (192.168.75.3) with Microsoft SMTP Server (TLS) id
 15.0.1130.7 via Frontend Transport; Wed, 20 Jan 2016 10:43:38 +1100
John

Do you allow a direct connection to your server for employee and support access?  That is, direct instead of VPN?
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Costas Georgiou

ASKER
Sorry John, i did not get your question.

With direct access do you mean Outlook anyware?
Outlook anyware : yes
John

How do you access your servers from a remote location?
SOLUTION
Mal Osborne

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Mal Osborne

⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Costas Georgiou

ASKER
Malmensa: Thanks, i agree,, i am working on that now.
We have a Cisco router and no firewall.. Just trying  to figure that out..
Jeff Glover

If you just have a Cisco router, then use an ACL to do what Malmensa recommended
Mal Osborne

Yep, either an ACL on the router, or reconfig of Exchange should work just fine.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Costas Georgiou

ASKER
@ Malmensa: could you please shed some light on the Exchange configuration if possible.
Thanks
ASKER CERTIFIED SOLUTION
Costas Georgiou

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Costas Georgiou

ASKER
no one pointed out the solution of remove the backup MX records