Re: Receiving Unknown Non-Deliverables

From: Damian N Leibaschoff [MSFT] (damianl_at_online.microsoft.com)
Date: 08/19/04


Date: Thu, 19 Aug 2004 11:17:50 -0500

Hi,
This could be someone just sending spam with bogus accounts, when the
receiving end tries to bounce the email, it sees that it came from your
domain (doesn't care about the user), and sends it back to you (on this case
your ISP) and it is accepted since most likely they have a catch all for
your domain. Then, after you download that, your server may generate an NDR
stating that the user does not exist and try to send that outbound. Not much
you can do in regards to the first part, you could disable NDRs to the
Internet or only accept emails sent to users hosted on your local domain at
the protocol level (this will not work with the POP3 connector).

Regards,
Damian

-- 
Damian N. Leibaschoff, MS IST, MCSE
Microsoft Corporation
Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
"KevinK" <anonymous@discussions.microsoft.com> wrote in message
news:8eea01c485f9$325c30b0$a501280a@phx.gbl...
> Setup
> SBS2003 with Exchange using POP3 download from ISP.
> I've gone through the "Make sure Exchange is not a Relay
> Agent stuff", etc. TWICE.
> Trend CSM - current, daily download.
>
> I am receiving several (5 to 10 / day) non-deliverable
> reports.
>
> The non deliverable e-mails are being sent from bogus
> userids at my domain to ids I have no idea who they are.
> And the bounce says the non deliverable e-mail was sent
> an hour earlier then the ND is generated.  It looks like
> a time zone thing.
>
> Any ideas what to check ??
>
> I intend to shut down my e-mail clients except when in
> use for the next couple of days, and may even shut down
> exchange over night. and see what happens.  I can then
> see if these appear in the ISPs que's via Webmail.
>
> My gut feel says the ISP is open and allowing these
> through, but I don't have any way to identify if that is
> the case.
>
> So how do I proceed to figure out what's going on ?
> I'm good with Exchange, but by no means a pro.
>
> Thanks
>
> Kevin K., MCSE


Relevant Pages

  • Re: Advice needed - running Exchange
    ... the router to your nic ... You'll need to have your ISP create two additional DNS records for your ... delivery is set to the Exchange mailbox, ... I currently only have one NIC in my SBS server ...
    (microsoft.public.windows.server.sbs)
  • Re: Advice needed - running Exchange
    ... Outlook experts for confirmation on this if you like...I've seen it happen, ... You will want to keep both the exchange and isp accounts in there for ... with the Exchange mailbox. ... server, or can I just use the one. ...
    (microsoft.public.windows.server.sbs)
  • Re: Email set-up
    ... What type of public IP address is provided by the client's broadband ... magma.ca and coverme.com - either directly or through a friendly ISP ... both of these needs to be changed to point to the public IP of the SBS. ... Exchange may actually be fairly easy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Possible to use another email address for replies?
    ... Exchange, I get the ISP address as return address. ... On the E-mail Addresses tab, ... you have to change the recipient policy in ESM. ...
    (microsoft.public.windows.server.sbs)
  • Re: Advice needed - running Exchange
    ... Exchange mailbox. ... You'll need to have your ISP create two additional DNS records for your ... Run the Connect to Email and the Internet Wizard on SBS ... I currently only have one NIC in my SBS server ...
    (microsoft.public.windows.server.sbs)