I finally spoke to the guys who where working on this late last night. They suggest that these spammers are forging there IP's, since they are not listed in our address list and our server is allowing this. Sorry I'm such a novice but is this possible and if so how would we guard against this? Wouldn't the server be able to tell that this was forged??
Technically, it is possible in some cases to forge IPs. However, it is extremely difficult with TCP (while simple with UDP). Trying to forge IPs from thousands of servers in a DDoS attack using TCP is nearly impossible.
However, before guessing what might have happened, you may want to read my previous post:
"The key questions here are "Were these E-mails addressed to local users?" (anyone can send unlimited E-mail *to* your users) and "If they were not to local users, did IMail actually relay them?" (if not, IMail handled the situation correctly)."
Looking at the IMail SMTP log file should give you a much better idea of what is happening.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
