Exch 2003 - Someone Relaying Email Through Server - Thousands an Hour
I apologize if this is posted somewhere. My company is getting killed by someone pounding our server. My issue is that being thrown into the IT role, my boss has insane expectations and if I can not resolve this without paying someoneI'm risking getting canned even though my boss is the one who forced me into the IT role. Anyway, so the basic jist of our problem is this:We set up an Exchange Server several months ago. We've been running fine until about a week ago when people emailing in to our company started reporting bounce messages, or worse, no message back at all. I rebooted the server, all the email seemed to come through. All is well.. About an hour later, it started happening again. And again... Today it all came to a head when no matter how many times I rebooted, no email. So I start poking around online and through some troubleshooting guides found that someone is sending hundreds of thousands of emails through our Exchange Server. When I logged in this afternoon, the Queue was over 400,000 emails. I found something on Microsoft (http://support.microsoft.com/default.aspx?kbid=909005) whichI tried. Followed the directions line for line. It has been somewhere around 3 hours and the load has not stopped. It is growing by several hundred emails every few minutes. I have deleted somewhere around 600,000 emails and they still continue to come in. Is there something else that I can do to block whoever the heck this is?? Anyways, so my question is, can ANYONE help? I am at a complete loss here. Even if I can find someone to remote into our Server and give me some insight I am at that point of despiration! Thanks in advance for anyone that can help here! Please email me at martinenglish@ascentive.com(NOSPAM)- please DO NOT reply to any other email linked with this post.
February 21st, 2008 3:46am

To add - I have configured everything I could find for relaying / connections / authentication on SMTP, POP3, and IMAP to allow only specific users and/or the IP addresses of our servers. I also got a brainfart to pull the network cable on the machine and even after that messages still kept piling up in Queue. So my hope is that I did actually block what we needed, but there are so many messages that they are still filtering in from whereever on the server. The one thing I DIDN'T know was that restarting SMTP would cause all the frickin email to queue up from scratch! UGH!! It was over 300,000 messages and I restarted SMTP for something someone suggested to try and was not thrilled that4 hours of Queuing went down the toilet. So just letting the machine run its course through the night and will see what happens tomorrow. In the mean time, any thoughts are still appreciated by this newbie!
Free Windows Admin Tool Kit Click here and download it now
February 21st, 2008 4:58am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics