KB 151
How do I configure an MS Exchange server to not allow relaying?
Article:151 Created:2002-01-25 11:26:21 Categories: E-mail Security
Question or Symptom
I've got an MS Exchange server and it's apparently been used to relay spam. Do you have any information about how to configure it to not do this?
Resolution
With versions of Exchange Server below 5.0 it is impossible to configure the server to be a secured relay. If your Exchange Server version is below version 5.0 the recommended path is to upgrade to at least Exchange server 5.5 Service Pack 2 with the encapsulated SMTP relay address patch.
There are several links listed below. The first is a third-party service where you can go to their website, plugin the IP address of your mailserver, and it will run a test to see if your mail server is misconfigured.
If your mail server accepts the test message that the automated test tries to relay through it, the test will report that your mail server is an open relay. This does indicate that your server is misconfigured, but it might not be true that your server is relaying.
If a mail server is configured properly, when someone, including this test, tries to relay through it, the mail server should refuse to accept the message. A common misconfiguration is for the mail server to accept the mail, then bounce it. This is better than relaying, but it is still a problem that needs to be fixed. To a spammer, that server will look like an open relay, and they will deliver hundreds, thousands, perhaps millions of messages to it, that it will then have to bounce. This will obviously affect the performance of your mail server. A second issue with this misconfiguration is that you can be used in a denial of service attack against someone else.
The links following the link for the open relay test are all articles on how to properly configure a MS Exchange server. They explain both how to prevent your Exchange server from being an open relay, and how to fix the "accept/bounce" misconfiguration.
Related URLS
http://www.mail-abuse.com/an_sec3rdparty.html http://www.microsoft.com/technet/security/bulletin/fq99-027.asp http://www.exchangeadmin.com/Articles/Index.cfm?ArticleID=7696 http://nocops.pacific.net.sg/serviceLink/mailrelaycheck.html