Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Relaying on, but queues are full

Status
Not open for further replies.

reamrodb

IS-IT--Management
Apr 10, 2002
6
US
We have turned off the relays on our Exchage 5.5 servers, but we still seem to have spam in the queues. we have tried to relay though a telnet session and it is teling us that relaying is not allowed. So, is the spam just getting caught in the queue or is relaying still occuring???
 
Check the queues and find out what is in them. Delete the spam or act on the queues.
 
Well, let me clarify a bit. I didn't mean that those queued messages were not spam related, but rather that they could be the NDR's of spam attempts. Depending on how you configured, or shut off relaying, the IMS may still accept the DATA portion of an SMTP message, before deciding that it won't relay the message. If this is the case, the IMS will generate an NDR that will sit in your queue if the sender's address is bogus.
 
Ah. In that case you haven't done the second part of the anti relaying...

Just turning off relaying is less than half the battle.
 
OK I'll bite. what's the second part of anti relaying????
 
Read my FAQ on relaying in this forum. It shows how to REALLY secure your Exchange server from relaying.
 
Thanks for the tip. Have read the FAQ and already am using the techniques you described. Cannot relay in telnet session. One question: we have turned on CLIENTS THAT SUCCESSFULLY AUTHENTICATE check box. What will this exactly do? We have not had any problems with our email with this option turned on.

Finally, going back to my original question: does anyone else have queues full of spam or NDRs?
 
Yes, I've had that problem too. I followed all the steps to make sure the server cannot be used as a relay server. I went online and ran a test on one of the spam-combat sites to confirm my server was secured. A few min later after they sent an email probe I saw that probe in the queue. The server refused to relay but still included the probe in the queue, than after some time it dropped it. Not sure why it happens. Let me add I also run an email filter in my IMS, so anytime I see the new spam domain in the queue I add it to the filter list, day by day less emails appear in a queue. I guess that works for me.
 
We just discovered that our Exchange 5.5 has been allowing relaying. Oops. We've shut down IMS, set Exchange to prevent relaying, attempted to clear the queues, then started it up again. The server slows way down. When we stop IMS, the out queue is full of spam. Does anybody know what's going on? This happens even if we disconnect the server from the network; it's isolated. Seems that a program is running to generate the spam?

And what is the official method of clearing the queues?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top