-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I would be very worried if I were you , if your machine is relaying mail messages regardless of who the sendor is , It is most probably already used by more then one spammer , in time when people get spam mail with the ip address of your server , it will be blacklisted and passed on between mail admins to block ....
you should block your server to relay messages only from you'r local network , look here: http://support.microsoft.com/default.aspx?scid=kb;EN-US;q310380 I'd use a linux based mail relay on a DMZ subnet , to relay messages to the exchange 2000 machine (just a tip....) Cheers TheOg TheOg - ----- Original Message ----- From: "GP" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, March 22, 2002 7:47 PM Subject: SMTP Relay possible issue with exchange > I'm running an exchange 2000 server and I think someone may be > using the exchange server to send mail using smtp. The system was > originally setup by a consultant. Can someone tell me first how to > be sure and second how to prevent this from happening. I looked > at the smtp virtual settings under virtual server and these are > some of the settings which have me concerned. Under |Access > Control|Authenticate the following items are checked: Anonymous > Access, Basic Authentication, Integrated Windows Authentication. > (The only users that I need to have the ability to send messages > are those within my domain which are connecting using Outlook and > some via OWA.) How does exchange use authentication when it comes > to sending and recieving smtp mail?? Another setting that has me > concerned is under Relay Restrictions which has the following > option checked: Allow all computers which successfully > authenticate to relay, regardless of the list above. Are these > settings correct for my environment using Outlook and OWA? Any help > would be greatly appreciated. > > GP -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com> iQA/AwUBPJ3TQSXZhGjHgDflEQIrBwCgzG3LmHKKOwl/a6qzYra9HK43o3wAoNUV 9YTMXHnenip4K/TEHzy485N8 =EUpP -----END PGP SIGNATURE-----