We use GFI Mail Essentials to manage the spam on our Exchange 2K3 server. Until recently it has been doing a great job. However, we are now getting spam slipping through where the message ID, From and Reply *look* like they are from someone in our domain, however the user name is not someone in the GAL (or any other user on the system). The only real clue is in the return path. I've told Exchange (and GFI) to ignore users not in the directory. I've posted a sample header below (our server, domain, and IP have been changed to protect the innocent...)
Any ideas on how to stop this? Any help would be greatly appreciated!
Microsoft Mail Internet Headers Version 2.0
Received: from 67.12.12.123 ([222.73.247.127]) by SERVER.domain.local with Microsoft SMTPSVC(6.0.3790.1830);
Fri, 13 Apr 2007 06:11:03 -0400
X-Originating-IP: 151.193.215.94 by smtp.222.73.247.127; Fri, 13 Apr 2007 06:10:52 -0500
Message-ID: <eadtfvMVYXXmurriel@domain.com>
From: "Millie Carroll" <murriel@domain.com>
Reply-To: "Millie Carroll" <murriel@domain.com>
To: murriel@domain.com
Subject: Prest1ge Repl1cas startling repl1ca w4tches for you
Date: Fri, 13 Apr 2007 06:10:52 -0500
Content-Type: text/plain;
Content-Transfer-Encoding: 7Bit
Return-Path: contact@in2connect.net
X-OriginalArrivalTime: 13 Apr 2007 10:11:04.0746 (UTC) FILETIME=[0BB6C0A0:01C77DB4]
Any ideas on how to stop this? Any help would be greatly appreciated!
Microsoft Mail Internet Headers Version 2.0
Received: from 67.12.12.123 ([222.73.247.127]) by SERVER.domain.local with Microsoft SMTPSVC(6.0.3790.1830);
Fri, 13 Apr 2007 06:11:03 -0400
X-Originating-IP: 151.193.215.94 by smtp.222.73.247.127; Fri, 13 Apr 2007 06:10:52 -0500
Message-ID: <eadtfvMVYXXmurriel@domain.com>
From: "Millie Carroll" <murriel@domain.com>
Reply-To: "Millie Carroll" <murriel@domain.com>
To: murriel@domain.com
Subject: Prest1ge Repl1cas startling repl1ca w4tches for you
Date: Fri, 13 Apr 2007 06:10:52 -0500
Content-Type: text/plain;
Content-Transfer-Encoding: 7Bit
Return-Path: contact@in2connect.net
X-OriginalArrivalTime: 13 Apr 2007 10:11:04.0746 (UTC) FILETIME=[0BB6C0A0:01C77DB4]