Daily Technology News, Tips, and Reviews | Subscribe to Jason Slater Technology BlogTechnology Feed | Join Jason Slater on TwitterTwitter | Thursday 2nd September 2010

Exchange 2007 Anti-Spam NDR frustrations

By Jason Slater
  • DiggThis
  • Share

Since implementing the Exchange 2007 Anti-Spam filters we have been experiencing a higher number of NDR (Non Delivery Report) messages going out as a result of spam – fortunately our second level mail filter is catching most of them (not an edge server).

We were hoping Spam messages might get silently dropped but some do appear to be bouncing back – not an ideal scenario especially as we don’t want to become victims of a reverse NDR attack.One option has been to use Recipient Filtering to automatically block emails sent to any unknown recipients however Exchange is still trying to bounce some back to the purported sender (I say purported because much of the Spam isn’t actually from where it says it is from).

Your message has encountered delivery problems
to the following recipient(s):

unknown@somedomain.com
(Was addressed to unknown@somedomain.com)
Delivery failed
550 5.1.1 User unknown

No recipients were successfully delivered to.

Final-Recipient: rfc822; unknown@somedomain.com
Action: failed
Status: 5.1.1 (Permanent failure – addressing: bad destination mailbox address)
Remote-MTA: dns; mailserver.somedomain.com
Diagnostic-Code: smtp; 550 5.1.1 User unknown
SMTP-Remote-Recipient: unknown@somedomain.com

It isn’t a big problem thanks to our second level mail filter but it is frustrating. The odd thing is that the NDR reports are disabled on the Exchange Server (unless of course the message above isn’t technically an NDR for some reason) – as we can see in Organization Configuration -> Hub Transport -> Remote Domains.

Exchange 2007 Anti Spam NDR frustrations

I will try and get to the bottom of this problem and report when I found out more.

I only recently learned that the Edge Transport rules agent and the Hub Transport rules agent offered slightly different configuration options (Configuring Exchange 2007 Hub Transport role to receive Internet mail) so looking ahead, it may be prudent to implement the Edge Transport Server role for dealing with the massing amount of Spam. I heard the news recently that our current second level mail filter provider are making their platform Edge compatible which could be of benefit.

Further Reading

Related

2 comments so far

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.