Hello Friends,
I was wondering if anyone could tell me what I'm doing wrong here... I just set up exchange a couple of weeks ago, and am still confused about the settings which never seem to work logically the way they're supposed to (well, according to my logic at least).
Basically, I want to stop these bastards at hinet.net from sending mail through my server. Here's a picture of the queue. This means that they're using my server to relay, does it not?:
Here's some of the addresses that are in the queues:
Judging from the domains, it looks like the messages are using Chinese or Korean encoding. Does this mean that my relay is open, plus somebody jacked my postmaster account? I've already tried changing the Administrator password. I even deleted the postmaster email address from the Administrator account, and still get the same thing...
I've set up a sniffer on the inside of our network, and none of these messages are originating internally.
So I tried blocking the IP address range of those domains (168.95.4.1 - 168.95.4.254) using the global deny list, which doesn't seem to work. Are my settings incorrect?:
I also tried to change the access settings in the smtp virtual server as such, with no luck:
Can anyone tell me what I'm doing wrong? I can't prevent this darn IP range from using my server!
I WOULD try unchecking anonymous access, but whenever I do that nobody can send anything at all to my users from the outside!!!
Thanks for your help,
Chris
I was wondering if anyone could tell me what I'm doing wrong here... I just set up exchange a couple of weeks ago, and am still confused about the settings which never seem to work logically the way they're supposed to (well, according to my logic at least).
Basically, I want to stop these bastards at hinet.net from sending mail through my server. Here's a picture of the queue. This means that they're using my server to relay, does it not?:
Here's some of the addresses that are in the queues:
Judging from the domains, it looks like the messages are using Chinese or Korean encoding. Does this mean that my relay is open, plus somebody jacked my postmaster account? I've already tried changing the Administrator password. I even deleted the postmaster email address from the Administrator account, and still get the same thing...
I've set up a sniffer on the inside of our network, and none of these messages are originating internally.
So I tried blocking the IP address range of those domains (168.95.4.1 - 168.95.4.254) using the global deny list, which doesn't seem to work. Are my settings incorrect?:
I also tried to change the access settings in the smtp virtual server as such, with no luck:
Can anyone tell me what I'm doing wrong? I can't prevent this darn IP range from using my server!
I WOULD try unchecking anonymous access, but whenever I do that nobody can send anything at all to my users from the outside!!!
Thanks for your help,
Chris