Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Non Delivery Reports are not being sent outside organisation

Status
Not open for further replies.

chaucer

IS-IT--Management
Jun 12, 2003
6
0
0
GB
Our NDR's are being forwarded to the Administrators mailbox, but are never recieved by the sender. I have checked our MailSweeper in case it is removing them but it definitly is not. I have a very thorough understanding of the mailsweeper rules and have them fully documented so am confident there are not being removed here.

Is there an exchange 5.5 setting to block non delivery reports?
 
Open your Internet Mail Service Properties from the "Connections" Option in Exchange 5.5 Administrator.

Click on "Advanced Options"

There's an option to disable / enable out-of-office responses to the Internet.

Hope this helps.
 
Yes, that fixed it, I can see it passing through MailSweeper now. It was the Disable Automatic Replies to the Internet that was blocking it.

My next problem however is that the reply address is blank and our SMTP service providor rejects all outgoing email with blank from addresses. How can I configure the from address for Non delivery reports, so that they are recieved by the sender from a system address such as postmaster@chaucerplc.com? Is it delibrately blank to stop NDR loops, if so as long as postmaster@chaucerplc.com exists there will never be a loop so wouldn't make sense.
 
The NDRs come with an envelope that has a blank sender because they are system messages (as mandated in RFC 821, see page 15 of There is no way to circumvent this is Exchange 5.5. The message body headers for these messages have a FROM: of postmaster@yourdomain.com, this is the bit of the message that people see as the sender when they open the message.
 
Ok, that makes sense. So the problem lies with the configuration of our outgoing SMTP service providor. I will ask them to remove this "Security Feature". I would have thought that a more secure configuration would be to only accept incoming SMPT connections based on IP. This would allow us to send system messages whilst ensuring only email from our SMTP server is processed.
 
Well... although the RFCs say NDRs must be created, they are increasingly used against you these days - a reverse NDR attack uses your server's NDR responses to send spam to thousands of spoofed sending addresses. So blocking NDRs these days is increasingly the norm - we've been blocking our outbound NDRs for at least 2 years. Although this is the first time I've heard of an ISP that blocks ALL NDRs sent via them. But it might be the beginning of a net-wide trend.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top