Tracking down Outgoing Spam in Exchange 2003

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



A week or so ago our server was blacklisted on Spamcop, and we started
getting blocked by Comcast for spam.

I'm trying to track down the source of this spam so I can kill it at
the source, but so far I'm not having much luck.

I've checked all the security settings--I don't allow relaying, and
only have one other computer, our listserv, in the organization
allowed to send email through the server.

I've enabled message tracking and have tried to narrow things down,
but so far I've found it useless since I can't have it show me only
outgoing mail. It shows me all the spam and email we have both
incoming and outgoing which doesn't help much.

I've also checked the queue, but it doesn't show me an excess of
messages waiting to be delivered.

So is there some way to figure out where in the world this email is
originating? I'm assuming it's somewhere within the organization.

We have Exchange 2003 Enterprise SP2 in a cluster on Windows Server
2003 Enterprise SP2.

Thanks.

.



Relevant Pages

  • Re: How to do rDNS. WAS: RE: educating rDNS violators
    ... It's done in the DNS server. ... As a spam prevention measure, a lot of end-user Internet providers are ... Using your own mail server as a slave to the ISP's mail server will add ...
    (Security-Basics)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... When you enable recipient filtering on the SMTP virtual server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Anyone succesfully stopped Reverse NDR Attacks in exchange 2000?
    ... to their filtering servers and the Spam stops filling your Exchange Queues ... and destined to an non existing address on your server. ... connecting addresses as there are spam sent. ...
    (microsoft.public.exchange2000.admin)
  • Re: Relay for spam?
    ... Now my ISP is complaining about being a relaay for spam. ... a SMTP mail sever set up as an open relay. ... A proxy server usually is set up so that people on the internal IP ... An open proxy allows ...
    (Ubuntu)