Domain spoofing

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi,

I run an Exchange 2003 SP1 (soon to become SP2) \ Windows 2003
SP1 server for a company. I host email for two publicly registered
domains. We also use a spam filter located on the same physical
server upstream from the email server. For our purposes, this
configuration works acceptably. I have SPF records for both domains
with softfail enabled -- both companies websites are hosted outside of
my network.

Recently, users in one of the domains informed me that their inboxes
were overwhelmed with a number of NDRs and bouncebacks from various
external email systems. Their domain had been hijacked and used by
spammers.

I have checked and rechecked, I am not an open relay. And I believe
that I also have enough rules setup in my spam filter to block many of
the obvious attacks.

In looking at the bouncebacks \ returned email headers:

1) The bottom up received from header (the first message handoff)
shows the correct domain and ip address and
2) the email messages actually sent were spam and the return path
address was an email distribution list (the display names were bogus)
that happens to coincide with the domain name

What happened and how can I prevent this from happening again?

Thanks for your help!

.



Relevant Pages

  • Re: Domain spoofing
    ... however configure your distribution lists to only accept mails from ... SP1 server for a company. ... We also use a spam filter located on the same physical ... The bottom up received from header (the first message handoff) ...
    (microsoft.public.exchange.admin)
  • Re: Domain spoofing
    ... SP1 server for a company. ... We also use a spam filter located on the same physical ... The bottom up received from header (the first message handoff) ... That doesn't mean that the headers weren't forged. ...
    (microsoft.public.exchange.admin)
  • Re: How to send NNTP "cancel" message?
    ... Microsoft does not publish this list. ... So if the first message contains a word or phrase that triggers a spam filter, ... Most of the canceled messages appear on the Google Groups server. ... How to send NNTP "cancel" message? ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Filtering SPAM with Linux
    ... You need to setup a mail server on your proxy box which will collect ... all incoming mail at port 25 and then apply SPAM filter there. ... setup procedure and you can follow some nice websites/papers on this setup. ...
    (Security-Basics)
  • Bounced messages
    ... I'm currently running exchange 2003 server with IMF as a spam filter in front ...
    (microsoft.public.exchange.admin)