Exchange Server - Unknown Sender

Asked By create_share
21-Nov-09 02:32 PM
Hi!

My users are still receiving messages from the e-mail addresses that do not
exist in my global address list like no-reply@mydomain.com even after
selecting "Block Messages sent to recipients not listed in the Global Address
List" in Sender Reputation Filter Under Anti-spam settings in Exchange 2007.

Is there a way i can block these e-mails?

Thanks!
Postini
(1)
Sender
(1)
Recipients
(1)
Appliance
(1)
Antispam
(1)
  Lanwench [MVP - Exchange] replied to create_share
21-Nov-09 02:48 PM
What you selected would block inbound mail to recipients not found in AD.
So, it does not matter if the *sender* is not in AD - the recipients of these
messages clearly *are*.

Look into Postini or other hosted antispam gateway service/appliance to
handle spam filtering for you. Works a lot better and your users will get a
quarantine notice.
Create New Account
help
a 'find now', double clicked on the message and checked on the sending and receiving: Sender: " = ?windows-1251?B?V2FjaG92aWEgU3VwcG9ydA = = ? = " Recipients: Envelope Recipients: SMTP:beve68@cbcruiser.com; SMTP:bevbretz5993@sbcglobal.net; SMTP:beverlywade1@sbcglobal.net; SMTP:bevkallen@charter SMTP:beverts@hotmail.com; SMTP:beverlyjhamm1@jackpot.com; SMTP:beveryhills@90210.com; First off, the sender is not from our domain, and the Recipients looks like spam. Now I turned on ExchTransport Logging -> Smtp to maximum and I'm Discussions V2FjaG92aWEgU3VwcG9ydA (1) YnLbnZ2dnUVZWhednZ2d (1) YpqdnVrjJcs2sG3bnZ2dnUVZ (1) SMTP (1) ExchTransport (1) VridnfXw (1) AntiSpam (1) Recipients (1) What version of Exchange? Have you enabled Recipient Filtering? Are you running any kind Sp2. Where do I check on recipient Filtering? Yes I have a antispam service via Postini. Ok, Postini is a great Antispam service. Do you have the box checked under your SMTP VS
for Olddomain and Newdomain are Identical. User names are constant. In exchange manager I expanded Recipients – selected Recipients policies – selected E-Mail Addresses tab and entered the new domain name. Mail sent you Exchange Miscellaneous Discussions Cuddy.local (1) SMTP (1) LoneWizard (1) Zeus.Cuddy.local (1) Recipients (1) Newdomain (1) Olddomain (1) Windows (1) You updated the default recipient policy with your 168.0.16] mail from:vince@cuddylaw.com 250 2.1.0 vince@cuddylaw.com. . . . Sender OK rcpt to:vince@cuddymccarthy.com 250 2.1.5 vince@cuddymccarthy.com data 354 Ed Crowley MVP . Hello – The problem is resolved. A long time ago we used Postini to filter out spam. It was my understanding that the Postini service was cancelled when we installed spam filters on our exchange server. Our ISP never domain be setup like our old domain. Since the new domain was NOT register with Postini – Postini bounced back the emails. The ISP forwarded the new domain name directly to our server
a forwarding rule to explain this. When the other users receive the emails, just the sender's name is in the To: & From: header. Can anyone offer any explanation as to why this is happening? Thanks Exchange Admin Discussions Outlook 2003 (1) SMTP (1) Postini (1) Compsosinc (1 Recipients (1) Reseller (1) Did you double-check the user's mailbox in Exchange to see makes you think it's been forwarded? Why isn't it possible that all the recipients were BCC'd? Make sure you've got SP2 and filtering enabled in Exchange. , e le Thanks for the reply. There are no alternate recipients specified for this user. BCC. How do I check / stop the BCC? OK. Ah - you I'm a big fan of hosted services for this sort of thing. Check out Postini (you should go through a reseller to buy this, as Google won't be able user doesn't have easy access to the quarantined mail (to check for false positives). Postini and others can be configured to email the user once daily with a list of
Postini Service. . . . IMF v2. . .Exchange Server 2003 SP2 Exchange Server Good morning! Quick question (okay, those t gonna ever be right): We have several clients for whom we have set up Postini to combat that ever-so-lovely thing called UCE. Things are working pretty well with that. Before we introduced Postini into the mix I had IMF v2 enabled and configured (typically Gateway Threshold: 7-8 to have been done? Does having the IMF v2 enabled somehow affect - generally speaking - how Postini works? Thanks, Cary Exchange Admin Discussions Exchange Server 2003 (1) MSExhangeMU (1) SMTP (1) UceArchive Firewall (1) - IMF has nothing to do with how Positini works in terms of what Postini can and cannot filter. It's the first point / gateway for inbound mail, where IMF Action simply means mail won't be archived any more, and all the stuff that Postini misses (and Postini doesn't miss much, imo) now ends up in users' Junk Mail folders instead of that having the Gateway Action set to Archive creates a situation where e-mail that Postini has tagged as spam is being sucked into the UCEArchive by the IMF. Now, I