Re: SMTP Server Remote Queue Length Alert question
- From: "Les Connor [SBS Community Member - SBS MVP]" <les.connor@xxxxxxxxxxxx>
- Date: Tue, 22 Aug 2006 12:49:09 -0500
It might be a better option to look at the Exchange AD filter, which when
enabled only allows incoming email to recipients who are listed in Active
Directory.
Without this filter, all email addressed to @domain.com is accepted,
regarless of whether the name (the part before the @) exists, or not. This
causes Exchange to send an NDR to the originating server, stating that no
such user exists. The vast majority of these NDRs are being attempted to
spoofed domains - they don't exist. This results in a bunch of queues, which
will all eventually time out. Given enough of these type of emails, your
server can be brought to it's knees; this is known a an NDR attack.
With the AD filter activated, this can't happen - your server simply rejects
the emails. There is a caveat, you can read about it in the SBS help file,
while you're reading about how to enable AD filter. You can enable
tarpitting to mitigate the caveat.
--
Les Connor [SBS Community Member - SBS MVP]
-----------------------------------------------------------
SBS Rocks !
----------------------
"Tell me and I'll forget. Show me and I'll remember. Involve me and I'll
understand." - Confucius
"[MVP] Nick Whittome" <nickwhittome@xxxxxxxxxxx> wrote in message
news:e9GtBRexGHA.2120@xxxxxxxxxxxxxxxxxxxxxxx
You could disable NDR's on the exchange server.
--
Nick Whittome
SBS and FS MVP
MijakiDK wrote:
Hi,
Recently, 2-4 days, I have recieved mails from SBS monitoring stating
"SMTP Server Remote Queue Length Alert".
When I look at the server I have 29 SMTP connections on retry.
I have various errors for the connections.
1. The remote server did not respond to a connection attempt.
2. An SMTP protocol error occurred.
3. Unable to bind to the destination server in DNS
4. No additional information available
All connections seems to be a result of spam, which btw is totally
over the top at the moment.
Any ideas on how to kill these connections?
/Kim Jahn
.
- Follow-Ups:
- Re: SMTP Server Remote Queue Length Alert question
- From: MijakiDK
- Re: SMTP Server Remote Queue Length Alert question
- References:
- Re: SMTP Server Remote Queue Length Alert question
- From: [MVP] Nick Whittome
- Re: SMTP Server Remote Queue Length Alert question
- Prev by Date: SBS 2003 R2 Premium Installation Order
- Next by Date: Ability to archive sent faxes in SBS 2003 Std
- Previous by thread: Re: SMTP Server Remote Queue Length Alert question
- Next by thread: Re: SMTP Server Remote Queue Length Alert question
- Index(es):
Relevant Pages
|