Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Outlook 2003 Rules Wizard and System Admin messages

Status
Not open for further replies.

Craino

IS-IT--Management
Oct 22, 2002
55
US
I have a couple users whose E-Mail addresses have obviously been captured somewhere by a zombie spam virus. Every day they both get upwards of 100+ System Administrator error messages from Russia as destination mail servers reject the messages they supposedly sent to bogus Russian addresses.

My problem is the Outlook 2003 rules wizard doesn't appear to process System Administrator type messages. Even constructing a simple rule to delete the messages based on common text in the message body doesn't work. It does delete messages that are "normal" E-Mail messages, but does nothing to the System Administrator rejects

I've looked in the application forms list and there isn't a "System Administrator" form for me to key on either.

Any ideas on how to block these incoming messages? My user would be eternally grateful...
 
There is a MS Exchange forum; But I think that if these msg's are spawning from a particular IP range, an admin can config xchangeServer to deny this IP range. If you do not do business with Russia, find the range and deny it.

rvnguy
"I know everything..I just can't remember it all
 
rvnguy,

A couple quick comments I should have made in my first post.

1) Our Exchange server is outsourced to a third party. We connect to it via RPC over HTTP. So I have very limited ability to effect Exchange server settings.

2) We do have some limited contact with Russia so I am hesitant to shut down the IP range or E-Mail domain entirely.

3) I was really hoping to find a solution to this via E-Mail rules as the solution could apply to other issues.

Thanks.
dec
 
Well, OK you can not shut down the complete range. Are these coming from a single or a small group of IP's?
If so record these and have your out sourced supplier set up a DOS for them. They should be very adept at this as this is there business.

rvnguy
"I know everything..I just can't remember it all
 
On a normal E-Mail message, I would click View/Options/Headers to look at this information (forwarding path, IPs, etc.)

However, since these are 550 reject System Administrator messages, I cannot do that. Opening up the message, the only View options I have are Previous, Next and Toolbars. If I click the Send Again... button to get something that more resembles a real E-mail, I have more View options, but nothing that lets me get at the headers.

I'll contact my vendor to see if they have any further ideas. Thanks for your suggestions rvnguy.
 
Sorry, I see your dilema...yes if these are eminating from outside they should be able to be traced back to the originating IP/isp.

This would disturb me greatly as I am sure it is for you.

rvnguy
"I know everything..I just can't remember it all
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top