Verification of From Address in SMTP Messages (155683)
The information in this article applies to:
- Microsoft Exchange Server 5.5
- Microsoft Exchange Server 4.0
- Microsoft Exchange Server 5.0
This article was previously published under Q155683 IMPORTANT: This article contains information about editing the registry. Before you edit the registry, make sure you understand how to restore the Registry if an issue occurs. For information on how to do this, view the "Restoring the Registry" online Help topic in Regedit.exe or the "Restoring a Registry Key" online Help topic in Regedt32.exe.
SYMPTOMS
Messages have an address in the From line that is not authentic.
CAUSE
This is done by using Telnet to connect to the mail host on port 25 and by typing RFC-821 SMTP commands to simulate the arrival of a new message. When these messages are received by the Microsoft Exchange Server Internet Mail Service (or Internet Mail Connector, in version 4.0), the address is compared to the Microsoft Exchange Directory. If the address matches a directory entry, the address is replaced in the message header. This means that the spoofed messages look identical to internally sent Exchange Server messages.
WORKAROUND
To work around this issue:
- On the File menu, click Properties.
If a Headers tab is present, the message was not sent by another Microsoft Exchange Server user in your organization.
STATUS
Microsoft has confirmed this to be an issue in Microsoft Exchange Server
versions 4.0 , 5.0 and 5.5. This issue was corrected in the latest
Microsoft Exchange Service Packs. For information on obtaining the Service
Packs, query on the following word in the Microsoft Knowledge Base:
Modification Type: | Minor | Last Reviewed: | 4/28/2005 |
---|
Keywords: | kbbug kbfix kbusage KB155683 |
---|
|