Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Monitoring E-mail for Suspicious Activity

Status
Not open for further replies.

bigA2003

MIS
May 6, 2003
8
0
0
CA
Hello All ...

What would be the best way to monitor inbound and outbound e-mail most securely on Exchange 5.5? (Without the users being aware of coarse) Only 3 people are going to be monitored.

Any suggestions would be helpful.

Thanks in advance,

biga2003
 
Turn on message tracking for your MTA and your Internet Mail Connector. Use the Message Tracking tool in Exchange Administrator to monitor the actual message traffic.

 
Hello .. thanks for the response ...

I belive the above way tracks the routing of the messages. Is there anyway to also record the message content? Basically ... copy ANY e-mails sent AND recieved from an individual so they can viewed later?


Thanks,

biga2003
 
Howdy:

Just a word of warning here.. Unless your company has an "Internet/Email Acceptable Use" policy and it has been circulated so that all employees know about it, what you are proposing can and has been interpreted as an invasion of privacy.

Murray
 
Thanks for the response ... I understand the legal issues ... this was requested of me by management and they were informed by their consel that is was legal. I also have an e-mail from management to "cover my butt". That red tape has been cut.

Any technical suggestions?

Thanks,

biga2003
 
-just an idea..
Like you said, Pburcin's way; tracks only the routing of the messages, but i think of a way and that after proceeding Pburcin's one; u should have by then the destination address of the receiver, so u spoof urs on time ,then u gets the mail
message.
the mail travels just once i think , so if u wanted that the original receiver gets the message i think u should then duplicate the message and resend it with ur address spoofed to the original sender's one.
 
sorry i haven't checked nicely ur first post and noticing "excheange 5.5" ,,
but still an idea on the subject..cheers
 
There is a option with the Exchange resource kit to activate Journalling for mailboxes and you can send all message (in & out) from mailboxes to a nominated mailbox or public folder. I no longer work with Exchange 5.5 on a regular basis but if you post the question in the Exchange 5.5 forum10 someone will know the answer.


Chris.


Indifference will be the downfall of mankind, but who cares?
 
Hey Chris .. thanks for the response ... I've enabled journaling .. but ... I am now journaling ALL Exchange Server users .. any idea how I can journal just three?

Thanks,

biga2003
 
Hi there, would it not be easy just to set permissions for these peoples mailbox so that you can have them delivered into another mail box as well and have that set up on outlook to deliver into personal folders, that way you would be able to check away at your leisure. That way, as long as outlook is open, anyemails will filter in within a minute or two of delivery into the exchange.

I have out look set up on a pc down here that sees all mailboxes, only because our computers go down from time to time, and so people can see urgent emails if necessary. I have to admit I do not know how this stands legally, as it was set up by the boss before I came here.

Hope this helps
 
Hi BigA,

It is relatively easy...

Within Exchange Administrator, for the three users in question, go to their mailbox properties and to the Delivery Options Tab. Check the Alternative Recipient and enter your mailbox (or the mailbox that you wish to recive the duplicate email to). This will sort out incoming emails.

To monitor Outgoing emails the only way that i know would be to look at their sent items regularly.

Good luck.
 
Visit who have a suite of plug-ins for everything other mail systems dont want you to have. Believe their AlwaysBCC is what you are looking for.

HTH
Mickey Shekdar
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top