Quantcast
Channel: Small Business Server forum
Viewing all articles
Browse latest Browse all 8539

how to prevent emails from a particular domain from going to the tarpit?

$
0
0

Hi!

We have SBS2011 with exchange 2010 SP2.  Our system receives thousands emails a day and all connectivity tests check out fine.  There is one domain that sends us emails, and they are evidently being sent to a tarpit.  Below is the smtp log of the exact email that shows what is going on.  I put in bold the line in question:

2012-12-03T19:06:53.476Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,0,mymailserver:25,remotemailserver:56383,+,,

2012-12-03T19:06:53.480Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,1,mymailserver:25,remotemailserver:56383,*,SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders,Set Session Permissions

2012-12-03T19:06:53.487Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,2,mymailserver:25,remotemailserver:56383,>,"220 mymailserver.mydomain.local Microsoft ESMTP MAIL Service ready at Mon, 3 Dec 2012 14:06:52 -0500",

2012-12-03T19:06:53.526Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,3,mymailserver:25,remotemailserver:56383,<,EHLO mail-remote1.remote.domain,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,4,mymailserver:25,remotemailserver:56383,>,250-mymailserver.mydomain.local Hello [remotemailserver],

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,5,mymailserver:25,remotemailserver:56383,>,250-SIZE 36577280,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,6,mymailserver:25,remotemailserver:56383,>,250-PIPELINING,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,7,mymailserver:25,remotemailserver:56383,>,250-DSN,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,8,mymailserver:25,remotemailserver:56383,>,250-ENHANCEDSTATUSCODES,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,9,mymailserver:25,remotemailserver:56383,>,250-STARTTLS,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,10,mymailserver:25,remotemailserver:56383,>,250-X-ANONYMOUSTLS,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,11,mymailserver:25,remotemailserver:56383,>,250-AUTH NTLM,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,12,mymailserver:25,remotemailserver:56383,>,250-X-EXPS GSSAPI NTLM,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,13,mymailserver:25,remotemailserver:56383,>,250-8BITMIME,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,14,mymailserver:25,remotemailserver:56383,>,250-BINARYMIME,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,15,mymailserver:25,remotemailserver:56383,>,250-CHUNKING,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,16,mymailserver:25,remotemailserver:56383,>,250-XEXCH50,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,17,mymailserver:25,remotemailserver:56383,>,250-XRDST,

2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,18,mymailserver:25,remotemailserver:56383,>,250 XSHADOW,

2012-12-03T19:06:53.540Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,19,mymailserver:25,remotemailserver:56383,<,MAIL FROM:<BE-RFI.remote@remote.domain> SIZE=78469,

2012-12-03T19:06:53.540Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,20,mymailserver:25,remotemailserver:56383,*,08CF87669323BEF4;2012-12-03T19:06:53.475Z;1,receiving message

2012-12-03T19:06:53.540Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,21,mymailserver:25,remotemailserver:56383,>,250 2.1.0 Sender OK,

2012-12-03T19:06:53.561Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,22,mymailserver:25,remotemailserver:56383,<,RCPT TO:<julie@mydomain.com>,

2012-12-03T19:06:53.598Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,23,mymailserver:25,remotemailserver:56383,>,250 2.1.5 Recipient OK,

2012-12-03T19:06:53.609Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,24,mymailserver:25,remotemailserver:56383,<,DATA,

2012-12-03T19:06:53.612Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,25,mymailserver:25,remotemailserver:56383,>,354 Start mail input; end with <CRLF>.<CRLF>,

2012-12-03T19:06:55.087Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,26,mymailserver:25,remotemailserver:56383,*,Tarpit for '0.00:00:01.320' due to 'DelayedAck',Delivered

2012-12-03T19:06:55.089Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,27,mymailserver:25,remotemailserver:56383,>,250 2.6.0 <10F478006938A048A5A508B7568AAE170289E1C9@ETA-NO-MBX02.eta.domain> [InternalId=81664] Queued mail for delivery,

2012-12-03T19:07:00.116Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,28,mymailserver:25,remotemailserver:56383,<,QUIT,

2012-12-03T19:07:00.117Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,29,mymailserver:25,remotemailserver:56383,>,221 2.0.0 Service closing transmission channel,

2012-12-03T19:07:00.117Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,30,mymailserver:25,remotemailserver:56383,-,,Local

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

I read that a solution to stop these emails from going to the tarpit is to set the maxacknowledgementdelay to zero, which will effectively turn off the tarpit and allow emails to pass through to the recipient.  However, I don't know if this is the best (or acceptable) solution.

Questions:

1.  If I run the command Set-ReceiveConnector "Custom App Receive Connector" -MaxAcknowledgementDelay 0,will I be opening up a security hole in our exchange server?

2.  Is there a better way to resolve this issue of the emails going to the tarpit that come from a single entity (a government office)?

Sincerely,

V2kmccl


Viewing all articles
Browse latest Browse all 8539

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>