Ureader.com  
Microsoft software help and Community
   home   |   control panel login   |   archive   |  
 
Exchange
2000.active.directory
2000.admin
2000.announcements
2000.app.conversion
2000.applications
2000.clients
2000.clustering
2000.connectivity
2000.development
2000.documentation
2000.general
2000.information.store
2000.interop
2000.kms
2000.misc
2000.protocols
2000.realtime.collabo.
2000.setup
2000.transport
2000.win2000
admin
application.conversion
applications
clients
clustering
connectivity
design
development
misc
mobility
setup
tools
  
 
date: Wed, 14 May 2008 07:00:16 -0700 (PDT),    group: microsoft.public.exchange.admin        back       


E-Mail Spoofing/Undeliverables   
Different users suddenly get a ton of undeliverable mail from time to
time.  Their addresses are being spoofed.  Is there anything I can do
from my server to minimalize this?  Or at least minimalize the
undeliverable messages that are being "returned" to them?  The source
IP addresses the spoofed messages are being sent from aren't
originating from my server at least.  By the way, I'm running Exchange
2007 SP1 as well as Forefront.
date: Wed, 14 May 2008 07:00:16 -0700 (PDT)   author:   unknown

Re: E-Mail Spoofing/Undeliverables   
anthony@necrofiends.com wrote:
> Different users suddenly get a ton of undeliverable mail from time to
> time.  Their addresses are being spoofed.  Is there anything I can do
> from my server to minimalize this?  Or at least minimalize the
> undeliverable messages that are being "returned" to them?  The source
> IP addresses the spoofed messages are being sent from aren't
> originating from my server at least.  By the way, I'm running Exchange
> 2007 SP1 as well as Forefront.

This is happening to everyone....please read recent posts as well as 
googling. There's really nothing you can do about this other than tell users 
to delete the bogus NDRs (rather, the legit NDRs to the bogus mail).
date: Wed, 14 May 2008 10:09:59 -0400   author:   Lanwench [MVP - Exchange]

Re: E-Mail Spoofing/Undeliverables   
"Lanwench [MVP - Exchange]"
 wrote:

>anthony@necrofiends.com wrote:
>> Different users suddenly get a ton of undeliverable mail from time to
>> time.  Their addresses are being spoofed.  Is there anything I can do
>> from my server to minimalize this?  Or at least minimalize the
>> undeliverable messages that are being "returned" to them?  The source
>> IP addresses the spoofed messages are being sent from aren't
>> originating from my server at least.  By the way, I'm running Exchange
>> 2007 SP1 as well as Forefront.
>
>This is happening to everyone....please read recent posts as well as 
>googling. There's really nothing you can do about this other than tell users 
>to delete the bogus NDRs (rather, the legit NDRs to the bogus mail). 

Content filtering can reduce the number of those NDRs that are
delivered to mailboxes, but there are lots of false-positives. It's
really hard to separate the "real" NDRs from the backscatter. BATV can
help, but it's far from trouble-free.

-- 
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@getronics.com
Or to these, either: mailto:h.pott@pinkroccade.com mailto:melvin.mcphucknuckle@getronics.com mailto:melvin.mcphucknuckle@pinkroccade.com
date: Wed, 14 May 2008 21:18:30 -0400   author:   Rich Matheisen [MVP]

Re: E-Mail Spoofing/Undeliverables   
Rich Matheisen [MVP]  wrote:
> "Lanwench [MVP - Exchange]"
>  wrote:
>
>> anthony@necrofiends.com wrote:
>>> Different users suddenly get a ton of undeliverable mail from time
>>> to time.  Their addresses are being spoofed.  Is there anything I
>>> can do from my server to minimalize this?  Or at least minimalize
>>> the undeliverable messages that are being "returned" to them?  The
>>> source IP addresses the spoofed messages are being sent from aren't
>>> originating from my server at least.  By the way, I'm running
>>> Exchange 2007 SP1 as well as Forefront.
>>
>> This is happening to everyone....please read recent posts as well as
>> googling. There's really nothing you can do about this other than
>> tell users to delete the bogus NDRs (rather, the legit NDRs to the
>> bogus mail).
>
> Content filtering can reduce the number of those NDRs that are
> delivered to mailboxes, but there are lots of false-positives.

Ayuh.

> It's
> really hard to separate the "real" NDRs from the backscatter. BATV can
> help, but it's far from trouble-free.

I don't know what BATV is....spill!
date: Thu, 15 May 2008 10:06:52 -0400   author:   Lanwench [MVP - Exchange]

Re: E-Mail Spoofing/Undeliverables   
"Lanwench [MVP - Exchange]"
 wrote:

>Rich Matheisen [MVP]  wrote:

					[ snip ]

>> It's
>> really hard to separate the "real" NDRs from the backscatter. BATV can
>> help, but it's far from trouble-free.
>
>I don't know what BATV is....spill!

Bounce Address Tag Validation

http://en.wikipedia.org/wiki/Bounce_Address_Tag_Validation
http://mipassoc.org/batv/
http://mipassoc.org/batv/draft-levine-smtp-batv-01.html


http://www.ietf.org/proceedings/04aug/slides/mass-6.pdf

-- 
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@getronics.com
Or to these, either: mailto:h.pott@pinkroccade.com mailto:melvin.mcphucknuckle@getronics.com mailto:melvin.mcphucknuckle@pinkroccade.com
date: Thu, 15 May 2008 16:51:14 -0400   author:   Rich Matheisen [MVP]

Re: E-Mail Spoofing/Undeliverables   
Rich Matheisen [MVP]  wrote:
> "Lanwench [MVP - Exchange]"
>  wrote:
>
>> Rich Matheisen [MVP]  wrote:
>
> [ snip ]
>
>>> It's
>>> really hard to separate the "real" NDRs from the backscatter. BATV
>>> can help, but it's far from trouble-free.
>>
>> I don't know what BATV is....spill!
>
> Bounce Address Tag Validation
>
> http://en.wikipedia.org/wiki/Bounce_Address_Tag_Validation
> http://mipassoc.org/batv/
> http://mipassoc.org/batv/draft-levine-smtp-batv-01.html
>
>
> http://www.ietf.org/proceedings/04aug/slides/mass-6.pdf

Gracias.

[I was kind of hoping it involved Bats. And TV. And a really cool stealth 
car. ]
date: Thu, 15 May 2008 19:48:36 -0400   author:   Lanwench [MVP - Exchange]

Re: E-Mail Spoofing/Undeliverables   
"Lanwench [MVP - Exchange]"
 wrote:

>Rich Matheisen [MVP]  wrote:
>> "Lanwench [MVP - Exchange]"
>>  wrote:
>>
>>> Rich Matheisen [MVP]  wrote:
>>
>> [ snip ]
>>
>>>> It's
>>>> really hard to separate the "real" NDRs from the backscatter. BATV
>>>> can help, but it's far from trouble-free.
>>>
>>> I don't know what BATV is....spill!
>>
>> Bounce Address Tag Validation
>>
>> http://en.wikipedia.org/wiki/Bounce_Address_Tag_Validation
>> http://mipassoc.org/batv/
>> http://mipassoc.org/batv/draft-levine-smtp-batv-01.html
>>
>>
>> http://www.ietf.org/proceedings/04aug/slides/mass-6.pdf
>
>Gracias.
>
>[I was kind of hoping it involved Bats. And TV. And a really cool stealth 
>car. ] 

Sorry. There is another BATV, though: Batavia Television. Not as
exciting as bats and TV but it does have the TV compnent. No car, and
probably no excitement.

-- 
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@getronics.com
Or to these, either: mailto:h.pott@pinkroccade.com mailto:melvin.mcphucknuckle@getronics.com mailto:melvin.mcphucknuckle@pinkroccade.com
date: Thu, 15 May 2008 20:40:36 -0400   author:   Rich Matheisen [MVP]

Google
 
Web ureader.com


    COPYRIGHT 2007, YARDI TECHNOLOGY LIMITED, ALL RIGHT RESERVE  |   contact us