Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Mail possibly not going through exchange?

Status
Not open for further replies.

purepest

Technical User
Jun 22, 2004
118
GB
Hi

We recently upgraded our infrastructure to Essential Business with Exchange 2007.

Since then we have been receiving a large amount of spam. We have Sophos Puremessage installed on the Exchange server with spam score turned on however most of the spam doesn't have a score.

Our spam filter has up to date definitions.

Does anyone have any ideas on where the problem could be? Sophos tell us that their software is configured properly so I can only assume that this can be a mail problem, possibly routing,

Cheers
Colin
 
Seems to me like all you need to do is look at the header of a spam email to see the path it took, and you'll know how it's being routed.

Or freeze the queues on the Security server to see if mail accumulates in them. I suppose it would be possible to misconfigure EBS so that mail skipped the security server and went straight to the mailbox server.

Dave Shackelford MVP
ThirdTier.net
TrainSignal.com
 
We have a queue on our edge server going to the mail server which I froze and no mail got past.

I then check the exchange server and it had a queue that receive mail from the edge server. I froze this and nobody got any mail until I released it.

I am currently moving puremessage from the exchange server to the edge server to see if that helps
 
I would definitely run PureMessage on the Edge and not the hub. Locally run 3rd party products are a necessary evil, and it's best when they are run on the edge and not up close to the hub\mailbox.

Dave Shackelford MVP
ThirdTier.net
TrainSignal.com
 
Except you need to account for hygiene of internal (only) mail. Only running it on the Edge doesn't account for this.

Pat Richard MVP
Plan for performance, and capacity takes care of itself. Plan for capacity, and suffer poor performance.
 
I guess if you are going to run it on the mailbox, do an initial full mailstore scan, and then run transport-level scans from then on. The problems I've seen have been from overscanning the mailbox database. I think the main way you could have a problem after doing things this way is if someone has a virus saved in their Drafts folder.

Dave Shackelford MVP
ThirdTier.net
TrainSignal.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top