Re: Exchange 2003 SP2 Relay Configuration



Ron <Ron@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

We are currently using exchange 2003 SP2 on a Windows server 2003
system. I notice emails that are in our outbound queue that I believe are
spam or emails being relayed thru our system. They all have postmaster as the
sender but never make it out of our queue thus I manually have to delete
them.

That sounds like they're just NDRs. Have you enabled recipient
filtering on your inflow server? If you don't accept email for
addresses that don't exist you won't be sending as many NDRs.

The reason the messages never leave the queue is because the domains
have no working email servers, the servers reply with 4XX status
codes, or the MX for the domain returns an address of 127.0.0.1 or
0.0.0.0, or some other sort of chicanery that prevents your server
from ever delivering the NDRs.

I do have SPF set.

Okay. That's good. But SPF won't do anything for you if the sender
doesn't publish the SPF TXT record for their domain. IOW, SPF helps
validate the sender and avoid "spoofed" addresses but does nothing to
prevent you fro receiving spam.

I belive that I have relaying secured but not quite sure. Under Relay
Restrictions i have 4 IP addresses that may relay thru the virtual server,
however the "Allow all computers which successfully authenticate to relay,
regardless of the list above" box is checked. Should this box be checked or
unchecked?

If the servers that you want to allow can authenticate then you don't
need the IP address in the permission list. If you have the IP
addresses in the list you don't need the authentication.

If I uncheck it do I have to manually enter all company
groups/users to relay and why would I want users to relay?

Ideally you'd want users to use Outlook email client software and
MAPI/RPC to send and receive email. Then there's no need for them to
use SMTP at all.

--
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@xxxxxxxxxxxxx
Or to these, either: mailto:h.pott@xxxxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxxxx
.



Relevant Pages

  • Re: SPAM Relay
    ... I've had this thought about my own server multiple times. ... It was unclear whether there was a misconfiguration of their mail servers, or our SPF records, so I removed the SPF records to see if we could clarify that. ... This will both lessen the likelyhood of your valid mail being classed as spam, and also reduce the likelyhood of a spammer successfully using your domain in spoofed addresses. ... setup to relay unless your administrator specifically changed the settings. ...
    (microsoft.public.windows.server.sbs)
  • Re: Joe Jobbing?
    ... be /nothing/ in the allow relay box. ... successfully authenticate" should /not/ be checked on your server. ... in the "Configure the Exchange Server to Block Open SMTP Relaying" ... > There are internal queues within Exchange that aren't visible to the queue ...
    (microsoft.public.exchange2000.admin)
  • Re: Help SBS2003 acting as relay
    ... If KB324958 testing shows no relay, ... I suspect that they move from target server to target server in order to ... That tip Ace for clearing the queue was excellent. ... Connector Scope - Entire Organization ...
    (microsoft.public.windows.server.sbs)
  • Re: exchange spamming
    ... > delete it from queue i get deleted and again start building up and my ... > spamming software for my mail server. ... E2k/2003 out of the box don't permit open relay, ... If you don't need authenticated relay, ...
    (microsoft.public.exchange.admin)
  • RE: Spam related problems
    ... Try running you mail server through multiple spam relay testers. ... and windows integrated authentication is checked off also. ...
    (microsoft.public.exchange2000.misc)