Hi
i want to know if there is a definitive way to check an STMP send log for relaying. I'm running exchange server 2007 - it is not an open relay - according to various test sites and my isp.
But there are log entries that look to me as if unknown emails are being sent through my server to recipients i have never heard of and that are accepted by the receiving mail server even tho the sender is unknown.
i am sure that no-one on my network is sending these emails and all workstations get scanned daily and are reporting no viruses.
This is an example from last night:
,>,EHLO mail.domain.co.uk,
,<,250-yakko.circlerdesigns.net Hello mail.domain.co.uk
,<,250-SIZE 52428800,
,<,250-PIPELINING,
,<,250-AUTH PLAIN LOGIN,
,<,250 HELP,
,*,62516,sending message
,>,MAIL FROM:<> SIZE=21992,
,>,RCPT TO:<angered@rodneyb.com>,
,<,250 OK,
,<,"550 """,
,>,QUIT,
,<,221 yakko.circlerdesigns.net closing connection,
,-,,Local
From this log i assume that my server has sent an email to 'angered' and that the receiving mail server has accepted it. Is this correct? And if so is this relaying?
i want to know if there is a definitive way to check an STMP send log for relaying. I'm running exchange server 2007 - it is not an open relay - according to various test sites and my isp.
But there are log entries that look to me as if unknown emails are being sent through my server to recipients i have never heard of and that are accepted by the receiving mail server even tho the sender is unknown.
i am sure that no-one on my network is sending these emails and all workstations get scanned daily and are reporting no viruses.
This is an example from last night:
,>,EHLO mail.domain.co.uk,
,<,250-yakko.circlerdesigns.net Hello mail.domain.co.uk
,<,250-SIZE 52428800,
,<,250-PIPELINING,
,<,250-AUTH PLAIN LOGIN,
,<,250 HELP,
,*,62516,sending message
,>,MAIL FROM:<> SIZE=21992,
,>,RCPT TO:<angered@rodneyb.com>,
,<,250 OK,
,<,"550 """,
,>,QUIT,
,<,221 yakko.circlerdesigns.net closing connection,
,-,,Local
From this log i assume that my server has sent an email to 'angered' and that the receiving mail server has accepted it. Is this correct? And if so is this relaying?