Re: Tracing Outlook/OWA senders

Tech-Archive recommends: Fix windows errors by optimizing your registry



If message was sent via mapi, you will not be able to track client IP.
For OWA you can check the client IP in the IIS log files.



James Chong (MVP)
MCITP | EMA; MCSE | M+, S+, Security+
msexchangetips.blogspot.com


On Feb 27, 2:01 pm, "Massimo" <bar...@xxxxxxxxx> wrote:
When Exchange (2003) delivers a SMTP message that has been created by a
Outlook or OWA user, the first IP address reported in the message headers is
the Exchange server's own one.

Is there any way to make it write the original client's IP address in the
message headers? If not, can this information be recovered somewhere (server
logs, IIS logs, etc.)?

I'm trying to trace a certain message back to its original sender, but the
only information I can find in the headers is the Exchange server's IP
address; of course I have the sender's address, and he must surely have been
using Outlook or OWA, so he needed to be authenticated by the domain... but
I need to trace it back to the actual computer where the message was
created; or at least make it possible to do this kind of tracing in the
future.

Can someone please help?

Massimo

.



Relevant Pages

  • Re: exchange OWA
    ... I also check IIS log and can't seem to find anything related to her logon but I can other people logon. ... I would also verify OWA is enabled on her account. ... Exchange MVP 2009 ...
    (microsoft.public.exchange.admin)
  • Re: OWA access problem
    ... i having problem with OWA connection from external, ... I check and check from IIS to Window Firewall but couldnt know whats wrong ... I had check this group and found a lot of OWA ... Can you see the external GET requests in the IIS log file? ...
    (microsoft.public.exchange.connectivity)
  • Re: Update Rollup 1 Trouble
    ... ActiveSync and Outlookup Anywhere are working fine. ... The user can log on to OWA, but they get primitive looking HTML with links ... In the IIS log, most of the Web parts that normally load ...
    (microsoft.public.exchange.admin)
  • Re: OWA Garbled
    ... You need to correpond to the IIS log which you can find in the location ... Try to login on the Backend server directly and see if ... you can browse OWA successfully. ... users that are on Exchange 2003 SP1 log ...
    (microsoft.public.exchange.clients)