To resolve this issue, create a recipient filter to prevent Exchange Server from accepting messages that are sent to recipients who do not exist. To do this, follow these steps.
Step 1: Determine whether the messages in the queues are NDR messages
- Start Exchange System Manager.
- Expand Servers, expand the Exchange Server server, and then click Queues.
- In the right pane, click a queue that contains many messages, click Find messages, and then click Find Now.
- View the Sender field of the returned items. If the sender of the message is postmaster name@name of your e-mail domain.com, the message is an NDR message. Double-click the message to view the external recipient of this message.
Follow steps 3 through 4 to view the messages in other SMTP queues. If most of the messages are from
postmaster name@name of your e-mail domain.com, you may be experiencing a reverse NDR attack. If most of these messages are not from
postmaster name@name of your e-mail domain.com, the computer may be configured as an SMTP open relay. Or, the computer may be the target of an authenticated relay attack.
For more information about how to resolve this issue, click the following article number to view the article in the Microsoft Knowledge Base:
895853
How to troubleshoot mail relay issues in Exchange Server 2003 and in Exchange 2000 Server
If the computer is configured as an open SMTP relay, or if the computer is the target of an authenticated relay attack, you do not have to continue to the "Step 2: Configure recipient filtering in Exchange Server 2003" section. However, if the computer is the target of a reverse NDR attack, create a recipient filter to prevent the Exchange Server 2003 server from accepting messages that are sent to recipients who do not exist. To do this, continue to the "Step 2: Configure recipient filtering in Exchange Server 2003" section.
Step 2: Configure recipient filtering in Exchange Server 2003
In the default Exchange Server configuration, e-mail that is sent to
name of your e-mail domain.com is accepted as local regardless of the e-mail alias to which the message is addressed. The e-mail alias is the part of the e-mail address that is on the left side of the @ (at sign). If an e-mail message is sent to an alias that is not valid, the SMTP service receives the whole message. Then, the SMTP service queries the Active Directory directory service for a user or distribution group that has a matching e-mail alias. For example, if an e-mail message is sent to
invalid user name@name of your e-mail domain.com, the SMTP service queries Active Directory for a user or distribution group that has the
invalid user name@name of your e-mail domain.com alias. However, if the e-mail alias does not exist, Exchange Server tries to send an NDR to the original e-mail message sender. This can cause many messages, queues, or both to appear in Exchange System Manager.
After you enable recipient filtering, Exchange Server validates the e-mail address before Exchange Server accepts the e-mail message. In this scenario, if no match for this e-mail alias appears in Active Directory, an NDR is still generated. However, in this scenario, it is the responsibility of the sending SMTP server instead of the Exchange Server server to generate and to deliver the NDR.
Note Recipient filtering is only available in Exchange Server 2003.
- Start Exchange System Manager.
- Expand Global Settings, right-click Message Delivery, and then click Properties.
- Click the Recipient Filtering tab, click to select the Filter recipients who are not in the Directory check box, and then click OK.
- When you receive the following message, click OK:
Connection, Recipient, and Sender Filtering must manually be enabled on specific SMTP virtual server IP address assignments as they are not enabled by default. For more information about how to enable any one or more of these filtering types, read their associated help.
- Expand Servers, expand the Exchange Server server, expand Protocols, expand SMTP, right-click Default SMTP Virtual Server, and then click Properties.
- On the General tab, click Advanced.
- Click Edit, click to select the Apply Recipient Filter check box, and then click OK three times.
Note If you are running Exchange Server in a front-end/back-end environment, recipient filtering must be enabled on the SMTP bridgehead server or servers.
After you enable recipient filtering, a certain technique may be used against the Exchange Server server to gather information about the valid e-mail addresses in your organization. This technique is known as a Directory Harvest Attack.
For more information about how to help prevent this kind of attack, click the following article number to view the article in the Microsoft Knowledge Base:
842851
SMTP tar pit feature for Microsoft Windows Server 2003
Step 3: Clean up the Exchange Server queues
Remove the UCE from the SMTP queues on the computer. To do this, follow these steps.
Warning During this process, all messages that are destined for external SMTP recipients are deleted. Internal e-mail messages and incoming e-mail messages from the Internet are not affected. These settings are temporary. The typical mail flow is restored after the Exchange Server SMTP queues are cleaned up.
- Start the Server Management tool.
- Expand Advanced Management, expand the Exchange organization, and then click Connectors.
Note This procedure requires an SMTP connector.
- Use one of the following methods:
- If the Exchange Server server does not have an SMTP connector, you must create one. To create an SMTP connector, follow these steps:
- Right-click Connectors, point to New, and then click SMTP Connector.
- In the Name box, type temporary smtp connector.
- Click Add, click the Exchange Server server in the Server list, and then click OK.
- Click the Address Space tab, and then click Add.
- Click SMTP, click OK, leave the asterisk in the E-mail domain box, and then click OK.
- Click the General tab.
- If the Exchange Server server has an SMTP connector, you must modify the connector. To modify this connector, follow these steps:
- Right-click this connector, and then click Properties.
Note If you have more than one SMTP connector, work with the one that contains an asterisk in the SMTP address space on the Address Space tab. - Click the General tab, and then note all the settings that are listed on this tab. You must restore these settings after you clean out the Exchange Server queues.
- Click Forward all mail through this connector to the following smart hosts, type an IP address that is not valid, and then enclose it in square brackets. For example, type [99.99.99.99].
- Click the Delivery Options tab, and then click Specify when messages are sent through this connector.
- In the Connection time list, click Run daily at 11:00 PM, and then click OK.
- In the left pane of the Server Management tool, expand Servers, expand the Exchange Server server, expand Protocols, expand SMTP, right-click Default SMTP Virtual Server, and then click Stop.
- When the default SMTP virtual server has successfully stopped, right-click Default SMTP Virtual Server, and then click Start.
- After the default SMTP virtual server has successfully started, wait for about 10 minutes.
Note When you restart the default SMTP virtual server, it re-enumerates the e-mail messages and puts them in a single queue for the SMTP connector that you configured. - In the left pane of the Server Management tool, expand Servers, expand the Exchange Server server, and then click Queues.
- Note the total number of messages that appear next to the SMTP connector that you configured. This number of messages must stabilize so that you can remove all the e-mail messages at the same time.
- Every 15 minutes, right-click Queues, and then click Refresh.
- Repeat step 12 until the number of messages in the SMTP connector queue remains constant.
- In the right pane, right-click the SMTP queue, and then click Find messages.
- In the Number of messages to be listed in the search list, click an appropriate number to let you remove all the messages at the same time. For example, if you have 900 messages that you want to remove, click 1000 in the Number of messages to be listed in the search list.
- Click Find Now.
- In the Search Results list, select all the messages. To do this, click a message, and then press SHIFT+PAGE DOWN.
- Right-click the selected messages, and then click Delete (no NDR).
- When you receive the following message, click Yes:
Are you sure you want to delete messages in the queue?
Note If you are removing many messages, the removal process may take a long time. - After the messages are successfully removed, close the Find Messages connector name dialog box.
- Right-click Queues, and then click Refresh.
- Note the total number of messages that appear next to the SMTP connector that you configured. This number of messages must be zero.
- Repeat steps 21 and 22 about every 5 minutes to make sure that the SMTP queue remains at zero messages. If the number of messages in the SMTP queue increases, Exchange Server is still processing messages for external delivery. In this scenario, continue to update the display until the number of messages in the SMTP queue stabilizes.
- Repeat steps 14 through 23 until the number of messages in the SMTP queue remains at zero. In this scenario, the Exchange Server SMTP queues have been cleaned of all the UCE.
After you have cleaned the Exchange Server SMTP queues, restore the SMTP connector configuration to its original settings. If you created a temporary SMTP connector, remove it. To do this, follow these steps:
- In the left pane of the Server Management tool, expand Connectors, right-click temporary smtp connector, and then click Delete.
- When you receive the following message, click Yes:
Are you sure you want to delete 'temporary smtp connector'?
Note After you modify or remove the SMTP connector, you must restart the SMTP virtual server.
For more information about how to resolve this issue, click the following article number to view the article in the Microsoft Knowledge Base:
895853
How to troubleshoot mail relay issues in Exchange Server 2003 and in Exchange 2000 Server