How to track who is sending spam through an Exchange server

exchangespam

I have an Exchange 2003 server that sent me an email this morning:

SMTP Server Remote Queue Length Alert

Looking in the queues using Exchange System Manager there were just over 16,000 spam emails waiting to be sent out. We send via an external filtering service which was disconnecting our server, presumably due to the level of outgoing spam.

How can I find out where this mail is coming from? Does Exchange 2003 log IP addresses etc somewhere?

Best Answer

You're probably an open relay. First thing's first is to lock down your setup. Here's some directions:
http://www.petri.co.il/preventing_exchange_2000_2003_from_relaying.htm