I had this question after viewing
Exchange 2010 Log Spam E-mail.
Greetings,
As part of my spam protection effort, I utilize Exchange Anti-Spam. As I get spam email, I identify the sending server IP (aaa.bbb.ccc.ddd) and then go into IP Block List and add aaa.bbb.ccc.0/24. For the most part, this works fine. However, on occasion, we're having legitimate senders being blocked due to their sending server being part of the aaa.bbb.ccc.0/24 network. If I go into the agent log, I get:
2016-03-23T15:13:08.32TG44
5,xxx.xxx.
xxx.xxx:25
,54.ccc.bb
b.aaa:5044
3,54.ccc.b
bb.aaa,,01
000153a409
52d0-32237
6de-9565-f
572c6-0000
00@domain.
com,,,0,Co
nnection Filtering Agent,OnMailCommand,Reject
Command,55
0 5.7.1
External client with IP address aaa.bbb.ccc.54 does not have permissions to submit to this server.,LocalBlockList,entry created by administrator,
Unfortunately, this is not very useful in identifying who the sender is. Is there a way to configure the IP Block to state the sender? Basically, I need a way to tell sender@email.com to send me an email and I can look at a log and see that sender@email.com was rejected. They often get NDRs that just say the sending server gave up after so many tries.
Any assistance would be great.
Thanks,
Jeremy
ASKER