This morning, our entire company received a spam message sent to users@ourdomain.on.ca, where ourdomain.on.ca is our actual domain. There is a distinguished name that this could correspond to:


Looking at the attributes though, there is no mail, no proxyAddresses, no signs that there is a mailbox configured there.

I did some LDAP queries, searching for:


But am not seeing any records. (I also search for known email addresses to ensure the tree was being searched properly.)

We are running Exchange 2003. Is there another place to look for group email addresses? Is it possible that the distinguished name is being automatically translated to an email address?

Greg Askew
    Containers and OU's don't have proxy addresses (although I suppose they could). Even if they did, they don't function as Distribution Groups (that I'm aware of). Where are you searching for the proxy address? Try creating a Saved query in ADUC using proxyaddresses=smtp:users@ourdomain.on.ca as the query string. (It sounds like that's what you did but you didn't say where you were performing the query). – joeqwerty Sep 18 '12 at 14:16
  • @joeqwerty I did the queries from "DC=ourdomain,DC=on,DC=ca", and recursed all the way down. I did find other users by doing this when I searched for their emails, but nothing for "users". – dangowans Sep 18 '12 at 14:31
  • I know what context you did the query from, I'm asking what tool you did the query from. Did you do it from ADUC? – joeqwerty Sep 18 '12 at 16:00
  • @joeqwerty I did my query using Apache Directory Studio. Would ADUC provide different results? – dangowans Sep 18 '12 at 16:59
  • Since I don't know what Apache Directory Studio is or where and how it binds to AD to perform it's query then yes, I would say run the query from ADUC and see what comes up. – joeqwerty Sep 18 '12 at 17:06

If you are referring to what appears in the To: field or the Outlook message header, that is irrelevant. You need to inspect the Exchange SMTP logs to determine the actual email addresses used to deliver the message.

The To: field may contain a bogus address that is non-existent, if the message has a valid address in the Bcc: field.

Greg Askew
  • The Exchange guy was back today, and we went over the logs. You were right. The spammer sent multiple messages BCCed to our users. The "users" email address in the To: field was there just for confusion. Thanks for your help. – dangowans Sep 19 '12 at 12:42

Well, first of all, before you spend more time trying to associate users@ourdomain.on.ca with a group or person in your environment, let me suggest that you're probably on a snipe hunt.

The actual problem (probably) below:

Like Greg Askew said, it is likely (if not almost certain) that there is no actual email address or group associated with the email address in the To: field (users@ourdomain.on.ca). It's fairly common practice, in fact, to send group emails to a bogus To: address, and BCC the actual recipients, when it might not be appropriate for the recipients to know about who all is being included in the email. This has legitimate applications (such as sending out a mass email to a number of disparate clients), as well as utility in sending out spam.

  • In fact, I often use this technique myself with distributions to multiple clients. I'll send an email to clientnotification@mydomain.tld, and BCC all the clients I want to get the email. They don't need to know about each others existence or status as my clients, or who all I'm sending to, and it cuts down on my workload, having to send one email instead of multiple emails.

The solution:

To mitigate or largely eliminate this kind of problem with spam reaching a group of recipients on your domain, there are a couple easy things to you can do within in Exchange. (As with most things, this functionality is more primitive in 2003 than in 2007 or 2010, but it's still there)

  1. Limit who may or may not send to the larger distribution groups.

    • It won't help if all your individual users were listed in the BCC (in which case, I'd suggest you need to defend your directory and mail server against Directory Harvest Attacks), but will in the event that this did get sent out to everyone via sending to the address of a large or global distribution list.

      • Our Global DL in Exchange 2003:

        • Global DL Permissions

        • (I Think there are a total of 8 people or groups in our company that can send an email to the global list, to give you an idea. Smaller groups are more permissive about accepting emails.)

  2. Limit some or all of you internal groups from receiving outside mail

    • This is a also a good idea, generally, because generally, you don't want people outside your organization sending emails to groups within it.

    • In Exchange 2003, this is enabled with the From authenticated users only tickbox in the above image.

The other beneficial side-effect of these setting is that you invariably get a luser doing a Reply All to some large distribution list with an asinine comment or acknowledgment of receipt (thanks!, was I supposed to get this?, etc.), and that's always unpleasant and inconvenient. Better cut them off before they spam the whole company with their invariably misspelled, ungrammatical, txt msg-style inanity.

Sounds like spoofing to me. I would recommend using a smarthost such as Postini to monitor your mail flow.

Garrett Dumas
  • Our outside emails hop through a similar service offered by Microsoft (http://www.microsoft.com/en-us/server-cloud/forefront/online-protection-for-exchange.aspx). This message happened to slip through the cracks. – dangowans Sep 18 '12 at 16:08