Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Receiving e-mails not addressed to user

Status
Not open for further replies.

mtb1996

IS-IT--Management
May 23, 2004
76
US
I've been reading a lot of the threads regarding SPAM mail, spoofed addressed, and the like trying to find a solution to this problem and I haven't found anything yet.

Some users in my organization (including myself) have been receiving e-mails not addressed to them. I've searched through the message headers and there's no reference to the valid e-mail address. Below is an example message header (I've only changed my domain info, the rest is the actual header) and some info about our configuration. I've seen this behavior for both MAPI and POP clients. How can this happen? Shouldn't Exchange reject mail to bogus e-mail addresses? I'm worried that I've been compromised.


*********
Microsoft Mail Internet Headers Version 2.0
Received: from mail pickup service by exchange.mydomain.com with Microsoft SMTPSVC;
Fri, 11 Jun 2004 01:32:31 -0700
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Content-Description: discrete arduous69.faun
x-pp-spamblocker-id: 1001
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1409
Received: from 69.37.234.206.adsl.snet.net ([69.37.234.206]) by exchange.mydomain.com with Microsoft SMTPSVC(5.0.2195.6713); Fri, 11 Jun 2004 01:32:24 -0700
X-Message-Info: N341AKC44LBUsbj0lyFIaBOY333JS445ybjRXkXH478
Received: from 232.196.200.74 by ip-298-8-2-9.cp.lilly@mydomain.com (AppleMailServer 60.2.4.0) id 77931161165 via NDR; Fri, 11 Jun 2004 08:30:32 -0100
Reply-To: "James Mathis" <lilly@mydomain.com>
From: "James Mathis" <lilly@mydomain.com>
To: "Lilly" <lilly@mydomain.com>
Subject: Need affordable phentermine or other drugs - Purchase online here
Date: Fri, 11 Jun 2004 02:28:32 -0700
MIME-Version: 1.0
Return-Path: <lilly@mydomain.com>
Message-ID: <exchangeiPrWzGI6dme00000318@exchange.mydomain.com>
X-OriginalArrivalTime: 11 Jun 2004 08:32:26.0584 (UTC) FILETIME=[A041E580:01C44F8E]
***************

Our config: Exchange 2000 SP3 on Windows 2K SP4 and all latest patches. Also on this machine, IIS and PolicyPatrol 3.0 (anti-spam), NAVMSE 2.5.

Thank you in advance for any help.
 
Most likely they are putting in your email address in the Blind Carbon Copy (BCC) field. Exchange by default (it may be possible to change this, but I've never tried) doesn't register any BCC email addresses in the Internet Headers.
 
Thanks for the tip. That makes perfect sense. So I guess the next question is... is there a way to log the BCC field at the server level??? I would hope so, simply for security's sake, I'd like to be able to track the path of all mail into my organization to rule out any security risks.
 
Nevermind... I seached for bcc in this forum and found my answer.
 
Upgrade to Symantec Mail Security for MS Exchange ver 4.5, it has great Anti-Spam and you can point it to Blacklist sites. It will refrence those before excepting the email. You can build a whitelist as well it may help.
 
We recently tested and then purchased Policy Patrol 3.0 for SPAM. I should check my filters and whitelists... a few are still getting through.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top