Exchange Server Forums

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Undeliverable messages NOT sent by me

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Microsoft Exchange 2003] >> Server Security >> Undeliverable messages NOT sent by me Page: [1]
Login
Message << Older Topic   Newer Topic >>
Limited time MSExchange.org offer! -- 1.Sep.2008 1:00:00 PM
TechGenix and SolarWinds have partnered to provide free copies of SolarWinds Exchange Monitor to all visitors who join the MSExchange.org Forums. SolarWinds Exchange Monitor is a handy desktop dashboard that continuously monitors Microsoft Exchange to deliver real-time insight into Exchange services, mail queue sizes, and host server health. Learn more about Exchange Monitor and the free offer!
Undeliverable messages NOT sent by me - 20.Sep.2006 3:56:48 AM   
belinda

 

Posts: 30
Joined: 16.Jan.2004
From: Sydney, Australia
Status: offline
I have been receiving undeliverable messages in my Inbox for email messages to people I do not know and emails I have not sent myself.

One instance is:


Return-Path: <notauser@ourdomain.com.au>
Received: (qmail 26396 invoked from network); 19 Sep 2006 21:19:26 -0400
Received: from unknown (HELO ourdomain.com.au) (201.25.164.111)
by 0 with SMTP; 19 Sep 2006 21:19:26 -0400
Message-ID: <5E1253C0.ADBDD55@ourdomain.com.au>
Date: Wed, 20 Sep 2006 06:49:44 +0500
From: "notauser" <notauser@ourdomain.com.au>
User-Agent: Mozilla/5.0 (compatible; Konqueror/2.2.1; Linux)
MIME-Version: 1.0
To: "user" <user@anotherdomain.net.au>
Subject: To you there has come a card from Postcard.com

I have checked our Exchange 2003 server and it does not appear to be an open relay so I'm wondering what is happening and how I stop this.
I've also received similar undeliverable emails where they are sent from my own email address, which is valid but bounce back either as undeliverable, or the recipients email server has rejected them.

Can anyone shed some light on what is happening here?

Thanks
Belinda
Post #: 1
RE: Undeliverable messages NOT sent by me - 20.Sep.2006 3:48:39 PM   
uemurad

 

Posts: 5573
Joined: 7.Jan.2004
From: California, USA
Status: online
You are feeling the secondary effects of unscruplous spammers.  Take the following example as an illustration:

Spammer broadcasts a message to random addresses of known SMTP domain names
(e.g. user1@abc.com, userXYZ@somecompany.com)
Spammer uses a random address as the reply address (e.g. notauser@ourdomain.com.au)

Consider what happens.  The mail systems for abc.com and somecompany.com receives the message.  They look up the users in their domains, and discover that no such users exist.  Those mail systems by SMTP specification are supposed to send a Non-Deliverable Report (NDR) back to where the message originated.  The problem is that according to the transmission, the message gets sent to notauser@ourdomain.com.au.

Yes, it stinks.  The SMTP specification was written during a more trusting time - it was assumed that senders would use accurate information.

_____________________________

Regards,

Dean T. Uemura
Microsoft MVP - Exchange
exchangeguy.blogspot.com
uemurad@yahoo.com

(in reply to belinda)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Microsoft Exchange 2003] >> Server Security >> Undeliverable messages NOT sent by me Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts