Exchange Server Forums

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

SMTP Security

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Microsoft Exchange 2003] >> Server Security >> SMTP Security Page: [1]
Login
Message << Older Topic   Newer Topic >>
Limited time MSExchange.org offer! -- 1.Sep.2008 1:00:00 PM
TechGenix and SolarWinds have partnered to provide free copies of SolarWinds Exchange Monitor to all visitors who join the MSExchange.org Forums. SolarWinds Exchange Monitor is a handy desktop dashboard that continuously monitors Microsoft Exchange to deliver real-time insight into Exchange services, mail queue sizes, and host server health. Learn more about Exchange Monitor and the free offer!
SMTP Security - 7.May2008 8:55:18 AM   
cterreforte

 

Posts: 89
Joined: 9.Aug.2007
Status: offline
Good morning all,

I have an Exchange Server 2003. What I want to know is how to check if my SMTP is secure. Is there an easy way to doing this? I just want to make sure my server is not easily accessible to hackers or others who want to compromise email accounts and send false messages from my users' accounts.

Thank you!
Post #: 1
RE: SMTP Security - 7.May2008 9:41:49 AM   
uemurad

 

Posts: 5488
Joined: 7.Jan.2004
From: California, USA
Status: online
Your question encompasses many elements - some you can control and some you cannot.

You can control whether your server is used by hackers to send out messages (relaying).

You can control whether your server is searched for valid addresses (tar-pitting, 3rd-party products to prevent directory harvest attacks).

You cannot prevent spammers from sending out messages with your domain (using existing and invalid user names) listed as the sending address.

_____________________________

Regards,

Dean T. Uemura
Microsoft MVP - Exchange
exchangeguy.blogspot.com
uemurad@yahoo.com

(in reply to cterreforte)
Post #: 2
RE: SMTP Security - 7.May2008 9:45:33 AM   
cterreforte

 

Posts: 89
Joined: 9.Aug.2007
Status: offline
How can I check or what measures can I take to ensure that my server is protected?

(in reply to uemurad)
Post #: 3
RE: SMTP Security - 7.May2008 10:45:52 AM   
uemurad

 

Posts: 5488
Joined: 7.Jan.2004
From: California, USA
Status: online
Download and run the Best Practices Analyzer (http://www.exbpa.com)
Read this article by Oz Ozugurlu: A lot of spam targeted at my Exchange server


_____________________________

Regards,

Dean T. Uemura
Microsoft MVP - Exchange
exchangeguy.blogspot.com
uemurad@yahoo.com

(in reply to cterreforte)
Post #: 4
RE: SMTP Security - 7.May2008 10:49:36 AM   
cterreforte

 

Posts: 89
Joined: 9.Aug.2007
Status: offline
Hello uemrad,

I have the ExBPA already. I disabled the annonymous access for my SMTP server. Would you have suggested this? Thanks for the link. I will take a look at it now.

(in reply to uemurad)
Post #: 5
RE: SMTP Security - 7.May2008 10:58:10 AM   
uemurad

 

Posts: 5488
Joined: 7.Jan.2004
From: California, USA
Status: online
If you disable anonymous access at your SMTP gateway, then any inbound messages from the Internet has to be able to authenticate or be rejected.  You'd only do that if you can guarantee that particular server would never receive messages from outside your organization, and even then I'd be reluctant to do so.

One thing you should do is configure relay restrictions.

_____________________________

Regards,

Dean T. Uemura
Microsoft MVP - Exchange
exchangeguy.blogspot.com
uemurad@yahoo.com

(in reply to cterreforte)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Microsoft Exchange 2003] >> Server Security >> SMTP Security Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts