Hi!
We have SBS2011 with exchange 2010 SP2. Our system receives thousands emails a day and all connectivity tests check out fine. There is one domain that sends us emails, and they are evidently being sent to a tarpit. Below is the smtp log of the exact email that shows what is going on. I put in bold the line in question:
2012-12-03T19:06:53.476Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,0,mymailserver:25,remotemailserver:56383,+,,
2012-12-03T19:06:53.480Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,1,mymailserver:25,remotemailserver:56383,*,SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders,Set Session Permissions
2012-12-03T19:06:53.487Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,2,mymailserver:25,remotemailserver:56383,>,"220 mymailserver.mydomain.local Microsoft ESMTP MAIL Service ready at Mon, 3 Dec 2012 14:06:52 -0500",
2012-12-03T19:06:53.526Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,3,mymailserver:25,remotemailserver:56383,<,EHLO mail-remote1.remote.domain,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,4,mymailserver:25,remotemailserver:56383,>,250-mymailserver.mydomain.local Hello [remotemailserver],
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,5,mymailserver:25,remotemailserver:56383,>,250-SIZE 36577280,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,6,mymailserver:25,remotemailserver:56383,>,250-PIPELINING,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,7,mymailserver:25,remotemailserver:56383,>,250-DSN,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,8,mymailserver:25,remotemailserver:56383,>,250-ENHANCEDSTATUSCODES,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,9,mymailserver:25,remotemailserver:56383,>,250-STARTTLS,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,10,mymailserver:25,remotemailserver:56383,>,250-X-ANONYMOUSTLS,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,11,mymailserver:25,remotemailserver:56383,>,250-AUTH NTLM,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,12,mymailserver:25,remotemailserver:56383,>,250-X-EXPS GSSAPI NTLM,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,13,mymailserver:25,remotemailserver:56383,>,250-8BITMIME,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,14,mymailserver:25,remotemailserver:56383,>,250-BINARYMIME,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,15,mymailserver:25,remotemailserver:56383,>,250-CHUNKING,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,16,mymailserver:25,remotemailserver:56383,>,250-XEXCH50,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,17,mymailserver:25,remotemailserver:56383,>,250-XRDST,
2012-12-03T19:06:53.527Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,18,mymailserver:25,remotemailserver:56383,>,250 XSHADOW,
2012-12-03T19:06:53.540Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,19,mymailserver:25,remotemailserver:56383,<,MAIL FROM:<BE-RFI.remote@remote.domain> SIZE=78469,
2012-12-03T19:06:53.540Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,20,mymailserver:25,remotemailserver:56383,*,08CF87669323BEF4;2012-12-03T19:06:53.475Z;1,receiving message
2012-12-03T19:06:53.540Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,21,mymailserver:25,remotemailserver:56383,>,250 2.1.0 Sender OK,
2012-12-03T19:06:53.561Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,22,mymailserver:25,remotemailserver:56383,<,RCPT TO:<julie@mydomain.com>,
2012-12-03T19:06:53.598Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,23,mymailserver:25,remotemailserver:56383,>,250 2.1.5 Recipient OK,
2012-12-03T19:06:53.609Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,24,mymailserver:25,remotemailserver:56383,<,DATA,
2012-12-03T19:06:53.612Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,25,mymailserver:25,remotemailserver:56383,>,354 Start mail input; end with <CRLF>.<CRLF>,
2012-12-03T19:06:55.087Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,26,mymailserver:25,remotemailserver:56383,*,Tarpit for '0.00:00:01.320' due to 'DelayedAck',Delivered
2012-12-03T19:06:55.089Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,27,mymailserver:25,remotemailserver:56383,>,250 2.6.0 <10F478006938A048A5A508B7568AAE170289E1C9@ETA-NO-MBX02.eta.domain> [InternalId=81664] Queued mail for delivery,
2012-12-03T19:07:00.116Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,28,mymailserver:25,remotemailserver:56383,<,QUIT,
2012-12-03T19:07:00.117Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,29,mymailserver:25,remotemailserver:56383,>,221 2.0.0 Service closing transmission channel,
2012-12-03T19:07:00.117Z,MYMAILSERVER\Windows SBS Internet Receive MYMAILSERVER,08CF87669323BEF4,30,mymailserver:25,remotemailserver:56383,-,,Local
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I read that a solution to stop these emails from going to the tarpit is to set the maxacknowledgementdelay to zero, which will effectively turn off the tarpit and allow emails to pass through to the recipient. However, I don't know if this is the best (or acceptable) solution.
Questions:
1. If I run the command Set-ReceiveConnector "Custom App Receive Connector" -MaxAcknowledgementDelay 0,will I be opening up a security hole in our exchange server?
2. Is there a better way to resolve this issue of the emails going to the tarpit that come from a single entity (a government office)?
Sincerely,
V2kmccl