I have determined over the past day or so that someone has been SMTP relaying thru my company's server to send spam. I have already taken the corrective measures to secure & lock-down the open relay.
My problem is that when I realized what was going on, I went immediately to Exchange system manager and found literally thousands of messages sitting in queue on the SMTP virtual server. Obviously I want to delete all of these messages so that they dont go out - I am not sure why they are sitting in queue either. The way I caught the relay spamming was because I couldnt send mail out to AOL or Hotmail accounts. Either because my IP has been added to the Mail Abuse list or because of all these spam mails hung up in queue.
I know that you can go to each queue and enumerate messages then delete all messages in the queue with or without sender notification. But my problem is that there are practically 500 or more queues for all the multiple domains to which the spam was trying to be sent. I'm wondering if there is any other way to enumerate and delete messages from queues other than having to go to each of the 500 or more queues and deleting the messages. I'm also curious as to why all these messages are stuck in queue to begin with. Any advice is appreciated. Thanks.
Brian
My problem is that when I realized what was going on, I went immediately to Exchange system manager and found literally thousands of messages sitting in queue on the SMTP virtual server. Obviously I want to delete all of these messages so that they dont go out - I am not sure why they are sitting in queue either. The way I caught the relay spamming was because I couldnt send mail out to AOL or Hotmail accounts. Either because my IP has been added to the Mail Abuse list or because of all these spam mails hung up in queue.
I know that you can go to each queue and enumerate messages then delete all messages in the queue with or without sender notification. But my problem is that there are practically 500 or more queues for all the multiple domains to which the spam was trying to be sent. I'm wondering if there is any other way to enumerate and delete messages from queues other than having to go to each of the 500 or more queues and deleting the messages. I'm also curious as to why all these messages are stuck in queue to begin with. Any advice is appreciated. Thanks.
Brian