Block anonymous relay

Андрей Михалевский 2,641 Reputation points
2024-04-25T09:11:04.3166667+00:00

Hi. Exchange 2019. I can telnet to do anonymous sending within the organization with any mailbox name. I believe this is a security issue. It works by default. How can I block this ? What are the recomendations ?

Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,083 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 142.2K Reputation points MVP
    2024-04-25T10:35:40.3633333+00:00

    Thats how SMTP works and is expected. If you didnt allow anonymous messages sent to users within your org, then you wouldnt be able to receive mail from the internet.

    Being able to send as any mailbox to your org is also expected because thats simply spoofing. To prevent that I would recommend a good antimalware/anti phishing product.

    You can also set this:

    https://learn.microsoft.com/en-us/answers/questions/56256/how-to-prevent-internal-email-spoofing-in-my-excha

    Open Relay on the other hand is disabled by default. No one externally should be able to send to another external org through your server.

    https://learn.microsoft.com/en-us/exchange/mail-flow/connectors/allow-anonymous-relay?view=exchserver-2019


0 additional answers

Sort by: Most helpful