Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Clarifying NDRs in the SMTP Queues

Status
Not open for further replies.

hende10

MIS
Aug 22, 2002
93
US
Like previous posters here, my SMTP Queues are filled with messages and domains. These messages are all from "postmaster@mydomain.com", so can I assume this is an automated NDR, generated by our server, to a spam email address? We do receive a lot of spam, which sometimes uses multiple arbitrary users that do not exist like abc123@mydomain.com. Is the only way to prevent this to disable automatic NDRs?

Also, the SMTP current sessions lists servers/IPs that I am not familiar with, from all over the world. I have since turned on logging for the MSExchangeTransport, but have yet to find any 1708 events. Does this mean that spammers are trying to log on to my server, but are unsuccessful?

Finally, is the best solution listed here is to disable authenticated relay? If so, how will it affect remote users using OWA and VPN?

Thanks,

Hende
 
How do you send/recieve emails?

if it is via a single ISP holding an MX record for you and relaying on your behalf

disable all relay except the IP of the mail server itself and your ISP

if you send/recieve mail yourself via DNS

disable all relay except the IP of the mail server itself but allow connection for all (should be a connection tab under the Default SMTP Virtual Server, its friday, its late, an i've polished off a bottle of wine, might get the PS2 online in a mo, lol)

this should work, i emphasis 'should'

i once had a SME that were sending and recieving via DNS and it continued to have connections gathering connection time (very dodgy), i put an SMTP filter in place (had a spare 'genuine' license for Mcafee) authorised only the mail server and the filter as being able to relay and the connections stopped but email continued come in and go out.

basically, a geniune connection or queue should be too quick for you to see in the SM unless you pause one of the queues

Gurner

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top