Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange Server 2010

Posted on 2016-08-22
10
Medium Priority
?
168 Views
Last Modified: 2016-08-29
Dear
I have critical case in my Organization mail server concerning my mail account ,I Have received many undelivered mails on my  mailbox for mails i never sent it before using a fake display name as shown below , also my queue  in mail server have full of mails sent it y me and i didnt sent any of these mails , Please advise .
-------------------------------------------------------------------------------------------
Delivery has failed to these recipients or groups:
dansto@online.no
Your message couldn't be delivered. Try to send it again later. If the problem continues, please contact your helpdesk.





Diagnostic information for administrators:
Generating server: nmmx3.nsc.no
dansto@online.no
#< #5.3.0 X-Unix; 73> #SMTP#
Original message headers:
Return-Path: <ibrahim.nakip@alkancit.com>
Received: from mail.alkancit.com (mail.alkancit.com [196.219.1.200])      by
 nmmx3.nsc.no (8.14.7/8.14.7) with ESMTP id u7M5qXt0014420
      (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT)      for
 <dansto@online.no>; Mon, 22 Aug 2016 07:52:37 +0200 (MEST)
Received: from fepakaqi (69.9.196.157) by mail.alkancit.com (172.16.1.26) with
 Microsoft SMTP Server (TLS) id 14.3.248.2; Mon, 22 Aug 2016 07:44:49 +0200
Message-ID: <F76695393C280C7686CFD65DAAD1E8C3@fepakaqi>
From: Angel <ibrahim.nakip@alkancit.com>
Reply-To: Angel <albinamakinna@gmail.com>
To: <selmon_rama@hotmail.com>
Subject: Cheerio
Date: Mon, 22 Aug 2016 06:21:12 -0700
MIME-Version: 1.0
Content-Type: text/plain; format=flowed; charset="utf-8"; reply-type=original
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 15.4.3555.308
X-MimeOLE: Produced By Microsoft MimeOLE V15.4.3555.308
Content-Transfer-Encoding: quoted-printable
X-Xxroufqwki: sw=gld ver=1.2 d=6m tld=com st=win
X-XClient-IP-Addr: 196.219.1.200
Received-SPF: neutral (nmmx3.nsc.no: 196.219.1.200 is neither permitted nor denied by domain of ibrahim.nakip@alkancit.com)
X-Scanned-By: MIMEDefang 2.78
0
Comment
Question by:Alkannetworks
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
10 Comments
 

Expert Comment

by:matedwards
ID: 41765083
Perhaps someone is spoofing your email address.

Have you got an SPF, DKIM and DMARC record set in your DNS zone file?

Do you have access to your DNS record?
0
 

Author Comment

by:Alkannetworks
ID: 41765101
Yes I have access to DNS record but you mean DNS for mail server or What?
0
 

Expert Comment

by:matedwards
ID: 41765107
Wherever you edit your MX record...
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 22

Expert Comment

by:robocat
ID: 41765135
You're getting bounced e-mails because somebody is spoofing your e-mail address.

>Delivery has failed to these recipients or groups:
>dansto@online.no

It seems that you're using an online mail provider by the name of "Telenor"? I don't speak Norwegian but this seems to be a telecom provider of some sorts?

If you're a customer of Telenor and you should ask them to protect their mailservers using SPF/DKIM because you can't do that yourself for a shared e-mail domain.

If you're actually working for Telenor, then ... what can say?
0
 

Author Comment

by:Alkannetworks
ID: 41765139
Dear
I have my own mail servers , and have never deal with this(Telenor) before
0
 
LVL 19

Expert Comment

by:suriyaehnop
ID: 41765275

X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 15.4.3555.308
X-MimeOLE: Produced By Microsoft MimeOLE V15.4.3555.308
Content-Transfer-Encoding: quoted-printable
X-Xxroufqwki: sw=gld ver=1.2 d=6m tld=com st=win
X-XClient-IP-Addr: 196.219.1.200
Received-SPF: neutral (nmmx3.nsc.no: 196.219.1.200 is neither permitted nor denied by domain of ibrahim.nakip@alkancit.com)

It seems that someone use windows live mail to spoof your email? Does 192.2191.200 is your mail server ip address?
1
 
LVL 22

Expert Comment

by:robocat
ID: 41768282
In your question you posted the headers that were part of the generated diagnostic information.

It would be interesting to see the actual headers of such a bounced e-mail, to see the path how these messages actually end up at your server. To do this, open such a message in outlook, then go to file->properties and copy the headers at the bottom of the window.
0
 

Author Comment

by:Alkannetworks
ID: 41770157
Dear suriyaehnop
Yes my Mail Server IP 196.219.1.200
0
 
LVL 22

Accepted Solution

by:
robocat earned 2000 total points
ID: 41770455
As far I can tell from the message:

1. The SPAM e-mails are being generated by IP 69.9.196.157 (fepakaqi ).
2. Your server (mail.alkancit.com [196.219.1.200]) accepts these SPAM e-mails and tries to forward them to the destination servers.
3. In this example the destination is nmmx3.nsc.no which refuses to accept this spam and generates the bounce message.

Is IP 69.9.196.157 known to you? If so, identify the sender machine and check why it is sending SPAM.

If this IP is unknown to you, then your server is acting as an open relay for this address, which is not good. Reconfigure your server correctly so it's not an open relay.
0
 

Author Closing Comment

by:Alkannetworks
ID: 41774436
thanks
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Windocks is an independent port of Docker's open source to Windows.   This article introduces the use of SQL Server in containers, with integrated support of SQL Server database cloning.
One-stop solution for Exchange Administrators to address all MS Exchange Server issues, which is known by the name of Stellar Exchange Toolkit.
Viewers will learn how to use the INSERT statement to insert data into their tables. It will also introduce the NULL statement, to show them what happens when no value is giving for any given column.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question