freedomit
Well-Known Member
- Reaction score
- 200
The Director of one of our clients is getting some double emails in his inbox mainly from spam providers. The client runs a fully patched SBS2011 server, the issue started earlier this year but then went away by itself and has resurfaced, rebooting the server doesn't fix it.
Looking at the SMTP receive logs every email he receives double of is also sent to an ex employee, however there account and email alias no longer exists, if i send an email to that email it bounces.
The SMTP log is below...
,2,192.168.44.2:25,38.99.252.6:57475,>,"220 mail.companydomain.co.uk Microsoft ESMTP MAIL Service ready at Fri, 4 Nov 2016 16:45:21 +0000",
,3,192.168.44.2:25,38.99.252.6:57475,<,EHLO ardourcraft.com,
,4,192.168.44.2:25,38.99.252.6:57475,>,250-mail.companydomain.co.uk Hello [38.99.252.6],
,5,192.168.44.2:25,38.99.252.6:57475,>,250-SIZE 52428800,
,6,192.168.44.2:25,38.99.252.6:57475,>,250-PIPELINING,
,7,192.168.44.2:25,38.99.252.6:57475,>,250-DSN,
,8,192.168.44.2:25,38.99.252.6:57475,>,250-ENHANCEDSTATUSCODES,
,9,192.168.44.2:25,38.99.252.6:57475,>,250-STARTTLS,
,10,192.168.44.2:25,38.99.252.6:57475,>,250-AUTH,
,11,192.168.44.2:25,38.99.252.6:57475,>,250-8BITMIME,
,12,192.168.44.2:25,38.99.252.6:57475,>,250-BINARYMIME,
,13,192.168.44.2:25,38.99.252.6:57475,>,250 CHUNKING,
,14,192.168.44.2:25,38.99.252.6:57475,<,MAIL FROM:<rachel.roman@ardourcraft.com> BODY=7BIT RET=HDRS,
,15,192.168.44.2:25,38.99.252.6:57475,*,08D40238A1A07BDF;2016-11-04T16:45:21.760Z;1,receiving message
,16,192.168.44.2:25,38.99.252.6:57475,<,RCPT TO:<john@companydomain.co.uk> NOTIFY=FAILURE,
,17,192.168.44.2:25,38.99.252.6:57475,>,250 2.1.0 Sender OK,
,18,192.168.44.2:25,38.99.252.6:57475,>,250 2.1.5 Recipient OK,
,19,192.168.44.2:25,38.99.252.6:57475,<,BDAT 8199,
,20,192.168.44.2:25,38.99.252.6:57475,*,Tarpit for '0.00:00:05',
,21,192.168.44.2:25,38.99.252.6:57475,>,"250 2.6.0 CHUNK received OK, 8199 octets",
,22,192.168.44.2:25,38.99.252.6:57475,<,BDAT 6339 LAST,
,23,192.168.44.2:25,38.99.252.6:57475,*,Tarpit for '0.00:00:01.592' due to 'DelayedAck',Delivered
,24,192.168.44.2:25,38.99.252.6:57475,>,250 2.6.0 <5689.24117001435.50353816009@smtp1.ardourcraft.com> [InternalId=3380387] Queued mail for delivery,
,25,192.168.44.2:25,38.99.252.6:57475,<,MAIL FROM:<rachel.roman@ardourcraft.com> BODY=7BIT RET=HDRS,
,26,192.168.44.2:25,38.99.252.6:57475,*,08D40238A1A07BDF;2016-11-04T16:45:21.760Z;2,receiving message
,27,192.168.44.2:25,38.99.252.6:57475,<,RCPT TO:<steve@companydomain.co.uk> NOTIFY=FAILURE,
,28,192.168.44.2:25,38.99.252.6:57475,*,Tarpit for '0.00:00:05',
,29,192.168.44.2:25,38.99.252.6:57475,>,250 2.1.0 Sender OK,
,30,192.168.44.2:25,38.99.252.6:57475,>,550 5.1.1 User unknown,
You can see the message is sent to John@ (the Director) and also Steve@ (the ex staff member) but john@ receives two copies. Every message that John receives two copies of is also sent to Steve?? There are no transport rules setup on Exchange and no rules in spam filter (Sophos PureMessage).
Looking at the message properties i can see a slight difference in the two messages but nothing points to the issue...
Received: from ardourcraft.com (38.99.252.6) by mail.companydomain.co.uk
(192.168.44.2) with Microsoft SMTP Server id 14.3.319.2; Fri, 4 Nov 2016
16:48:05 +0000
Date: Fri, 4 Nov 2016 12:43:56 -0400
MIME-Version: 1
Content-Type: text/html; charset="UTF-8"
To: <john@companydomain.co.uk>
Subject: Are you sure you're getting the best deal on cable/net services? New offers have incredible packages.
Reply-To: Rachel Roman <rachel.roman@ardourcraft.com>
Content-Transfer-Encoding: quoted-printable
From: Rachel Roman <rachel.roman@ardourcraft.com>
Message-ID: <5689.23925374435.157538236009@smtp1.ardourcraft.com>
Return-Path: rachel.roman@ardourcraft.com
X-MS-Exchange-Organization-AuthSource: SERVER.ukpro.local
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-AVStamp-Mailbox: Sophos;-1157447678;0;PM
X-PMWin-SpamScore: 12
Received: from ardourcraft.com (38.99.252.6) by mail.companydomain.co.uk
(192.168.44.2) with Microsoft SMTP Server id 14.3.319.2; Fri, 4 Nov 2016
16:45:22 +0000
Date: Fri, 4 Nov 2016 12:43:59 -0400
Subject: Are you sure you're getting the best deal on cable/net services? New offers have incredible packages.
Message-ID: <5689.24117001435.50353816009@smtp1.ardourcraft.com>
From: Rachel Roman <rachel.roman@ardourcraft.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1
Content-Type: text/html; charset="UTF-8"
To: <john@companydomain.co.uk>
Reply-To: Rachel Roman <rachel.roman@ardourcraft.com>
Return-Path: rachel.roman@ardourcraft.com
X-MS-Exchange-Organization-AuthSource: SERVER.ukpro.local
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-AVStamp-Mailbox: Sophos;-1157447678;0;PM
X-PMWin-SpamScore: 12
Any ideas?
Looking at the SMTP receive logs every email he receives double of is also sent to an ex employee, however there account and email alias no longer exists, if i send an email to that email it bounces.
The SMTP log is below...
,2,192.168.44.2:25,38.99.252.6:57475,>,"220 mail.companydomain.co.uk Microsoft ESMTP MAIL Service ready at Fri, 4 Nov 2016 16:45:21 +0000",
,3,192.168.44.2:25,38.99.252.6:57475,<,EHLO ardourcraft.com,
,4,192.168.44.2:25,38.99.252.6:57475,>,250-mail.companydomain.co.uk Hello [38.99.252.6],
,5,192.168.44.2:25,38.99.252.6:57475,>,250-SIZE 52428800,
,6,192.168.44.2:25,38.99.252.6:57475,>,250-PIPELINING,
,7,192.168.44.2:25,38.99.252.6:57475,>,250-DSN,
,8,192.168.44.2:25,38.99.252.6:57475,>,250-ENHANCEDSTATUSCODES,
,9,192.168.44.2:25,38.99.252.6:57475,>,250-STARTTLS,
,10,192.168.44.2:25,38.99.252.6:57475,>,250-AUTH,
,11,192.168.44.2:25,38.99.252.6:57475,>,250-8BITMIME,
,12,192.168.44.2:25,38.99.252.6:57475,>,250-BINARYMIME,
,13,192.168.44.2:25,38.99.252.6:57475,>,250 CHUNKING,
,14,192.168.44.2:25,38.99.252.6:57475,<,MAIL FROM:<rachel.roman@ardourcraft.com> BODY=7BIT RET=HDRS,
,15,192.168.44.2:25,38.99.252.6:57475,*,08D40238A1A07BDF;2016-11-04T16:45:21.760Z;1,receiving message
,16,192.168.44.2:25,38.99.252.6:57475,<,RCPT TO:<john@companydomain.co.uk> NOTIFY=FAILURE,
,17,192.168.44.2:25,38.99.252.6:57475,>,250 2.1.0 Sender OK,
,18,192.168.44.2:25,38.99.252.6:57475,>,250 2.1.5 Recipient OK,
,19,192.168.44.2:25,38.99.252.6:57475,<,BDAT 8199,
,20,192.168.44.2:25,38.99.252.6:57475,*,Tarpit for '0.00:00:05',
,21,192.168.44.2:25,38.99.252.6:57475,>,"250 2.6.0 CHUNK received OK, 8199 octets",
,22,192.168.44.2:25,38.99.252.6:57475,<,BDAT 6339 LAST,
,23,192.168.44.2:25,38.99.252.6:57475,*,Tarpit for '0.00:00:01.592' due to 'DelayedAck',Delivered
,24,192.168.44.2:25,38.99.252.6:57475,>,250 2.6.0 <5689.24117001435.50353816009@smtp1.ardourcraft.com> [InternalId=3380387] Queued mail for delivery,
,25,192.168.44.2:25,38.99.252.6:57475,<,MAIL FROM:<rachel.roman@ardourcraft.com> BODY=7BIT RET=HDRS,
,26,192.168.44.2:25,38.99.252.6:57475,*,08D40238A1A07BDF;2016-11-04T16:45:21.760Z;2,receiving message
,27,192.168.44.2:25,38.99.252.6:57475,<,RCPT TO:<steve@companydomain.co.uk> NOTIFY=FAILURE,
,28,192.168.44.2:25,38.99.252.6:57475,*,Tarpit for '0.00:00:05',
,29,192.168.44.2:25,38.99.252.6:57475,>,250 2.1.0 Sender OK,
,30,192.168.44.2:25,38.99.252.6:57475,>,550 5.1.1 User unknown,
You can see the message is sent to John@ (the Director) and also Steve@ (the ex staff member) but john@ receives two copies. Every message that John receives two copies of is also sent to Steve?? There are no transport rules setup on Exchange and no rules in spam filter (Sophos PureMessage).
Looking at the message properties i can see a slight difference in the two messages but nothing points to the issue...
Received: from ardourcraft.com (38.99.252.6) by mail.companydomain.co.uk
(192.168.44.2) with Microsoft SMTP Server id 14.3.319.2; Fri, 4 Nov 2016
16:48:05 +0000
Date: Fri, 4 Nov 2016 12:43:56 -0400
MIME-Version: 1
Content-Type: text/html; charset="UTF-8"
To: <john@companydomain.co.uk>
Subject: Are you sure you're getting the best deal on cable/net services? New offers have incredible packages.
Reply-To: Rachel Roman <rachel.roman@ardourcraft.com>
Content-Transfer-Encoding: quoted-printable
From: Rachel Roman <rachel.roman@ardourcraft.com>
Message-ID: <5689.23925374435.157538236009@smtp1.ardourcraft.com>
Return-Path: rachel.roman@ardourcraft.com
X-MS-Exchange-Organization-AuthSource: SERVER.ukpro.local
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-AVStamp-Mailbox: Sophos;-1157447678;0;PM
X-PMWin-SpamScore: 12
Received: from ardourcraft.com (38.99.252.6) by mail.companydomain.co.uk
(192.168.44.2) with Microsoft SMTP Server id 14.3.319.2; Fri, 4 Nov 2016
16:45:22 +0000
Date: Fri, 4 Nov 2016 12:43:59 -0400
Subject: Are you sure you're getting the best deal on cable/net services? New offers have incredible packages.
Message-ID: <5689.24117001435.50353816009@smtp1.ardourcraft.com>
From: Rachel Roman <rachel.roman@ardourcraft.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1
Content-Type: text/html; charset="UTF-8"
To: <john@companydomain.co.uk>
Reply-To: Rachel Roman <rachel.roman@ardourcraft.com>
Return-Path: rachel.roman@ardourcraft.com
X-MS-Exchange-Organization-AuthSource: SERVER.ukpro.local
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-AVStamp-Mailbox: Sophos;-1157447678;0;PM
X-PMWin-SpamScore: 12
Any ideas?