Any network/hardware specialists in the house?

Any network/hardware specialists in the house?

Author
Discussion

malman

2,258 posts

260 months

Tuesday 8th April 2008
quotequote all
Its not something simple like you are an open relay?

http://www.abuse.net/relay.html

judas

Original Poster:

5,992 posts

260 months

Tuesday 8th April 2008
quotequote all
No, that was my first thought as we were having some problems getting email through to some customers. Turned out that a now-redundant secondary MX record was pointing to a mailserver that had been blacklisted.

malman

2,258 posts

260 months

Tuesday 8th April 2008
quotequote all
Next time it happens ( this is an exchange server right?) freeze the outbound queues in Exchange system manager and see whether you still have stuff going out. If its going through exchange you will be able to see the stuff in the queues and the destinations. If its using exchange then tcpview (sysinternals) should show you which process is driving it as its likely to be using smtp to pump exchange.

If its outside exchange then tcpview again can help but you might need process monitor and process explorer to find all its registry keys etc to get rid.

"netstat -o" does pretty much the same as tcpview but tcpview is easier and prettier


Hope that helps


Tunku

7,703 posts

229 months

Wednesday 9th April 2008
quotequote all
I reckon after reading the thread, you have a maverick PC connected to your server. Do you have a antivirus on each of the PCs attached to the server? I would suggest a server based one that can broadcast updates to the PCs attached to the server.