Q
Problem solve Get help with specific problems with your technologies, process and projects.

Problems with email spoofing on SBS 2003

See the suggestions made to a member who is using Small Business Server 2003 and an Open Relay Filter with issues regarding email spoofing.

I am currently running Small Business Server 2003 and have an Open Relay Filter running on my Exchange server and SMTP connector -- both of which run locally. I've recently noticed a problem where the From field claims to be a local user sending spam and the To field is the same local user. How do I prevent spam being sent by local users?
There are very few, if any, situations that require your Exchange server to be an open relay. For most SBS scenarios, you will not need to permit any relay, even from workstations. Therefore, you can configure your default SMTP virtual server in the Exchange System Manager to deny relay from all hosts, except for those that you may specify.

The situation that you describe, in which the From field of messages claims to be from users on your network, is...

known as "spoofing." This is a tactic commonly used by spammers. Most anti-spam services, whether outsourced or hosted internally, are sophisticated enough to recognize spoof attempts and will block these messages. You can also setup a SPF record for your domain name that identifies which servers on the Internet are authorized to send on your behalf.

Do you have comments on this Ask the Expert Q&A? Let us know.

This was last published in May 2009

Dig Deeper on Small Business Server

PRO+

Content

Find more PRO+ content and other member only offers, here.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

-ADS BY GOOGLE

SearchWindowsServer

SearchEnterpriseDesktop

SearchCloudComputing

SearchSQLServer

Close