Suddenly getting a lot of SPAM but header shows SCL of -1?

I have Exchange 2010 with Forefront Protection for Exchange installed on the same box. About two weeks ago, I suddenly began getting a ton of spam messages and many users reporting an increase in junk mail. I started to research and found the SCL in the
headers is being set to -1 and allowing these mails through. I have 2 receive connectors configured. One is for external mails and the other is for internal things like copiers and it's secured by those particular IP addresses. I need to get this fixed
so any help is greatly appreciated. Below are a few of the headers from spam mails.
Received: from bawright.madbunwe.com (5.83.38.89) by MX1.PELLCITYSCHOOLS.NET
(10.0.0.15) with Microsoft SMTP Server id 14.3.169.1; Fri, 5 Sep 2014
14:12:00 -0500
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Ford Overstock <[email protected]>
Date: Fri, 5 Sep 2014 12:12:22 -0700
Subject: Rock-bottom discounts on 2014's
Message-ID: <20140905005946.24362.3293.20140905005946.24362.3293.20140905005946.24362.3293@mx1.madbunwe.com>
To: <[email protected]>
Return-Path: [email protected]
X-MS-Exchange-Organization-AuthSource: EXCHANGE01.PCSS.LOC
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-PRD: madbunwe.com
X-MS-Exchange-Organization-SenderIdResult: Pass
Received-SPF: Pass (EXCHANGE01.PCSS.LOC: domain of
[email protected]
designates 5.83.38.89 as permitted sender) receiver=EXCHANGE01.PCSS.LOC;
client-ip=5.83.38.89; helo=bawright.madbunwe.com;
X-MS-Exchange-Organization-SCL: -1
X-MS-Exchange-Organization-Antispam-Report: v=2.1 cv=aeNYw3Yt c=1 sm=1 tr=0
a=T8rIjO6mKJQ+94fJGo+fAg==:117 a=T8rIjO6mKJQ+94fJGo+fAg==:17
a=1zcUvo0hogkA:10 a=oS82QrVdJDkA:10 a=qE3gpJXiGUkA:10 a=kj9zAlcOel0A:10
a=E7ipFV9zAAAA:8 a=6YhcBzZrAAAA:8 a=8QrfYh5om_Q4riOErpgA:9
a=wWNLVvIxh3jk9zDA:21 a=I7hM4kbu4ljq4qH6:21 a=CjuIK1q_8ugA:10
a=bizVLaNEpWMA:10;OrigIP:5.83.38.89;SCL:-1
X-MS-Exchange-Organization-AVStamp-Mailbox: MSFTFF;1;0;0 0 0
Received: from macgroupus.wettrue.com (5.83.38.54) by MX1.PELLCITYSCHOOLS.NET
(10.0.0.15) with Microsoft SMTP Server id 14.3.169.1; Fri, 5 Sep 2014
13:33:23 -0500
Content-Type: text/html; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Message-ID: <20140905002627.4610.53475.20140905002627.4610.53475.20140905002627.4610.53475@mx1.wettrue.com>
Date: Fri, 5 Sep 2014 11:33:46 -0700
Subject: Adjusted Home Payment, 2.99 Pct. Ready
To: <[email protected]>
From: Home Payment-Reduction <[email protected]>
Return-Path: [email protected]
X-MS-Exchange-Organization-AuthSource: EXCHANGE01.PCSS.LOC
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-PRD: wettrue.com
X-MS-Exchange-Organization-SenderIdResult: Pass
Received-SPF: Pass (EXCHANGE01.PCSS.LOC: domain of
[email protected] designates 5.83.38.54 as permitted sender)
receiver=EXCHANGE01.PCSS.LOC; client-ip=5.83.38.54;
helo=macgroupus.wettrue.com;
X-MS-Exchange-Organization-SCL: -1
X-MS-Exchange-Organization-Antispam-Report: v=2.1 cv=aeNYw3Yt c=1 sm=1 tr=0
a=OWV+kUdfH3dG0gKaIM7UEA==:117 a=OWV+kUdfH3dG0gKaIM7UEA==:17
a=nkEXP-9RdN8A:10 a=j8_Z_fWWQ6cA:10 a=0-XR6fN9bSAA:10 a=kj9zAlcOel0A:10
a=M_il8B12AAAA:8 a=6YhcBzZrAAAA:8 a=8HlGpp5ipwlAm3L7SP0A:9
a=TetN-Dxqk35B8DMb:21 a=CjuIK1q_8ugA:10 a=_W_S_7VecoQA:10
a=F7vr65HLMrMA:10;OrigIP:5.83.38.54;SCL:-1
X-MS-Exchange-Organization-AVStamp-Mailbox: MSFTFF;1;0;0 0 0
Received: from novackmacey.adenclear.com (5.83.38.22) by
MX1.PELLCITYSCHOOLS.NET (10.0.0.15) with Microsoft SMTP Server id 14.3.169.1;
Fri, 5 Sep 2014 12:42:52 -0500
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
To: <[email protected]>
Reply-To: <[email protected]>
From: Massive Wood-Project Database <[email protected]>
Message-ID: <DKJHFWIN0984397599-HGYE-MailHost.20140905073329.4964.21612.sweaver@pellcityschools.net>
Subject: Download over 10,000 Father/Son projects
Date: Fri, 5 Sep 2014 10:43:14 -0700
Return-Path: [email protected]
X-MS-Exchange-Organization-AuthSource: EXCHANGE01.PCSS.LOC
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-PRD: novackmacey.adenclear.com
X-MS-Exchange-Organization-SenderIdResult: Pass
Received-SPF: Pass (EXCHANGE01.PCSS.LOC: domain of
[email protected] designates 5.83.38.22 as permitted sender)
receiver=EXCHANGE01.PCSS.LOC; client-ip=5.83.38.22;
helo=novackmacey.adenclear.com;
X-MS-Exchange-Organization-SCL: -1
X-MS-Exchange-Organization-Antispam-Report: v=2.1 cv=aeNYw3Yt c=1 sm=1 tr=0
a=v8PoIBesxqQR6kEepLZJ7g==:117 a=v8PoIBesxqQR6kEepLZJ7g==:17
a=rid0MFnRnVQA:10 a=TbDVZEha78UA:10 a=G9qHhN7WPskA:10 a=RUD0_apYOI4A:10
a=kj9zAlcOel0A:10 a=J9u9LQjwAAAA:8 a=6YhcBzZrAAAA:8 a=7uVIZRh44UQICufYe1YA:9
a=CjuIK1q_8ugA:10 a=ZN73Z-vY58wA:10 a=DGAAHIZb5w8A:10
a=MpIORKB7RiAA:10;OrigIP:5.83.38.22;SCL:-1
X-MS-Exchange-Organization-AVStamp-Mailbox: MSFTFF;1;0;0 0 0
Jeff Green MCSA/MCSE 2003, MCITP 2008

Hi,
You could have a look on the following blogs.
Exchange Server 2010 : Planning for Anti-Spam (part 2)
http://mscerts.programming4.us/application_server/exchange%20server%202010%20%20%20planning%20for%20anti-spam%20(part%202).aspx#eYjWBhtXuiPZ7xfF.99
Note: Microsoft provides third-party contact information to help you find technical support. This contact
information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
Please make sure the bypass is configured correctly on the receive connectors.
http://blogs.technet.com/b/msfss_stuff/archive/2011/12/01/fpe-issue-where-all-spam-is-missed.aspx
Best Regards,
Joyce
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.

Similar Messages

  • I get a lot of spam on my old mobileMe-alias. How do I delete that old .me adress?

    I am using my iCloud-account, but still I get a lot of spam to my old MobileMe-alias. How do I delete the adress? (They don´t show up in iCloud)

    [email protected] and [email protected] are the same thing - you can't actually delete the @me.com version.
    However you can deal with the problem by setting up a Rule to move all messages address to the @me.com address to the Trash, from which they will automatically be deleted after a week, so you won't even see them.
    Go to the Mail page at http://icloud.com ; click the cogwheel icon at bottom left and choose 'Rules'.

  • I'm suddenly getting a lot of popups

    Hi, I'm running Safari 8.0 and around a week ago I suddenly started getting popups everywhere, and ads on certain sites that never had them before - BBC, Google - I installed adblocker but it doesn't seem to have stopped. I tried unchecking " Allow WebGL" and "Allow Plugins" on the Safari prefs but it stopped a lot of embedded media from functioning.
    I've never had any problems like this before with any previous OS or any previous machine.
    Can anyone help?
    Thanks

    1. Safari > Preferences > Extensions
        Turn those off and relaunch Safari again.
        Turn those on one by one and test.
    2. Download  free  AdwareMedic by clicking “Download ” from here
         http://www.adwaremedic.com/index.php
       Install , open,  and run it by clicking “Scan for Adware” button   to remove adware.
       Once adware is removed, quit the app by clicking AdwareMedic in the menubar
        and selecting “Quit AdwareMedic”.
        To use manual method try this.
         http://www.thesafemac.com/arg-identification/
    Best.

  • HT4759 I'm getting a lot of spam in my icloud account and would like to change my icloud email address, how can I do this?

    After having a mac.com email for nearly 10 years I fell for a scam email and now am getting spammed daily in my email account.  I use this email account for everything and would like to either block the spam emails - although that's hard since they change their email address daily - or just get a new icloud email address.  I've researched this and have not found this easy.  Any suggestions on how to change my icloud email account? Keep in mind all my devices are connected through this email including iTunes.  Any help is appreciated - thanks!

    To get a new iCloud address you would have to create a new iCloud account and migrate your iCloud data to the new account.  If you want to do this, go to Settings>iCloud and tap Delete Account, and when prompted about what to do with the iCloud data choose Keep on [My iDevice].  Then set up a new iCloud account with a new ID, turn you iCloud data syncing back to On, and when prompted choose Merge to upload your data to the new account.  When you turn Mail to On you will get a new @icloud email address (@mac and @me addresses are no longer available).  Once your data is in the new account, you can just delete the old account from your other devices without saving the data on the device, then sign into the new one and the migrated data in the new account will be synced back to them.
    If you need to, you can change your iTunes ID to this new email address.  This guide explains how to change an Apple ID name, but you can follow this and edit the primary email address instead to change it: http://support.apple.com/kb/HE40.

  • Imac g5, screen issue, gets main and second display but only shows second which is 800x600, not the 1600x1400

    Hello,  i have a  power pc g5 running 10.3.5  i have a issue not being able to get the correct display to show. When it start up it comes up with a screen size of 800x600, which i can not change or select the main display, also the computer computer does not shut down or restart unless you hold the power button. Hopefully someone can help me, i am new to apples, i have a few for my kids and i am learning, any help would be appricated.  Thank you

    not sure how to update this , this ia  a imac 20 inch all in one desktop

  • I am getting lots of spam and dont know what settings to use

    Hi All
    I am not the greatest on my Mac but I am getting a lot of spam and not sure what settings I should apply to try and reduce the amount of spam I receive.
    Kind Regards
    Ian

    Whatever email client you are using, the spam settings are always found in the client's Preferences.  Some say Junk Mail while other may say Spam. 

  • Suddenly getting spam...help on config? postconf inside

    My company has about 25 mailboxes hosted on this server, recently we have all been getting a LOT of spam. I have noticed in the headers in emails that the spam scores are showing up very low, even for the very obvious "viagra" emails.
    Would greatly appreciate if someone could double check my config to point me in the right direction. Thanks!
    xserve0:~ root# postconf -n
    alias_maps = hash:/etc/aliases,hash:/var/mailman/data/aliases
    command_directory = /usr/sbin
    config_directory = /etc/postfix
    content_filter = smtp-amavis:[127.0.0.1]:10024
    daemon_directory = /usr/libexec/postfix
    debugpeerlevel = 2
    enableserveroptions = yes
    html_directory = no
    inet_interfaces = all
    mail_owner = postfix
    mailboxsizelimit = 0
    mailbox_transport = cyrus
    mailq_path = /usr/bin/mailq
    manpage_directory = /usr/share/man
    mapsrbldomains =
    messagesizelimit = 0
    mydestination = $myhostname,localhost.$mydomain,localhost,mail.intrix.org,intrix.org
    mydomain_fallback = localhost
    myhostname = xserve0.intrix.org
    mynetworks = 127.0.0.0/8
    mynetworks_style = host
    newaliases_path = /usr/bin/newaliases
    ownerrequestspecial = no
    queue_directory = /private/var/spool/postfix
    readme_directory = /usr/share/doc/postfix
    recipient_delimiter = +
    sample_directory = /usr/share/doc/postfix/examples
    sendmail_path = /usr/sbin/sendmail
    setgid_group = postdrop
    smtpdclientrestrictions = permit_mynetworks rejectrblclient bl.spamcop.net rejectrblclient list.dsbl.org permit
    smtpdenforcetls = no
    smtpdpw_server_securityoptions = cram-md5,gssapi,login
    smtpdrecipientrestrictions = permitsasl_authenticated,permit_mynetworks,reject_unauthdestination,permit
    smtpdsasl_authenable = yes
    smtpdtls_certfile = /etc/certificates/Default.crt
    smtpdtls_keyfile = /etc/certificates/Default.key
    smtpduse_pwserver = yes
    smtpdusetls = yes
    unknownlocal_recipient_rejectcode = 550
    virtualmailboxdomains = hash:/etc/postfix/virtual_domains
    virtual_transport = lmtp:unix:/var/imap/socket/lmtp
    xserve0:~ root#

    I don't mean to be argumentative, but I clicked on your google search link, and only found one link that said that spamcop was bad to use (article from 2004?). However, I found this recommendation in the SpamAssassin-2.43.readme:
    "There are several tests in the spamassassin configuration file which are
    turned off by default, namely the mail-abuse.org and bl.spamcop.net tests.
    The mail-abuse.org tests are RCVDINRBL, RCVDINRSS, and RCVDINDUL;
    the bl.spamcop.net test is called RCVDIN_BL_SPAMCOPNET."
    "These are commercial services, so you need to pay money to use them.
    Having said that, the bl.spamcop.net service gets my recommendation as the
    most useful blacklisting DNS service I've found. More information on it
    can be found at http://spamcop.net/bl.shtml ."
    http://www.cpan.org/modules/by-module/Mail/Mail-SpamAssassin-2.43.readme
    Also, I forward the spam that does get through my system to spamcop (and the FTC, and my spamassassin junkmail training account). So I would expect that since the spamcop list is in part created from my difficult spam - that spamcop would be more likely to be able to block said difficult spam.
    At the moment, in the last day or so, spamhaus has blocked about 91% of all of my spam, and spamcop as blocked about 4%.
    I am looking into using your suggestion of combined.njabl.org. Though, so very little spam gets through my system now, that I'm not sure it will catch anything.
    Cheers.

  • My back button and refresh button and my yahoo tool bar are dimmed a lot when I open up firefox. So as a result, I cannot use the back button nor my refresh button AND my yahoo toolbar disappears a lot. I have tried to get on your chat session but it is a

    <blockquote>Locked by Moderator as a duplicate/re-post.
    Please continue the discussion in this thread: [/forum/1/688252]
    Thanks - c</blockquote>
    == Issue
    ==
    I have another kind of problem with Firefox
    == Description
    ==
    My back button and refresh button and my yahoo tool bar are dimmed a lot when I open up firefox. So as a result, I cannot use the back button nor my refresh button AND my yahoo toolbar disappears a lot. I have tried to get on your chat session but it is always closed. I need one on one help. Please reply with resolution.
    == This happened
    ==
    Every time Firefox opened
    == two or three months ago
    ==
    == Firefox version
    ==
    3.6.3
    == Operating system
    ==
    Windows XP
    == User Agent
    ==
    Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 (BT-canvas) Firefox/3.6.3 GTB7.0 (.NET CLR 3.5.30729)
    == Plugins installed
    ==
    *-npdnu
    *npdnupdater2
    *Coupons, Inc. Coupon Printer DLL
    *Coupons, Inc. Coupon Printer Plugin
    *The QuickTime Plugin allows you to view a wide variety of multimedia content in Web pages. For more information, visit the QuickTime Web site.
    *6.0.12.448
    *RealPlayer(tm) LiveConnect-Enabled Plug-In
    *RealJukebox Netscape Plugin
    *Default Plug-in
    *Adobe PDF Plug-In For Firefox and Netscape "9.3.2"
    *BrowserPlus -- Improve your browser! -- http://browserplus.yahoo.com/
    *Shockwave Flash 10.0 r45
    *Yahoo Application State Plugin version 1.0.0.7
    *3.0.50106.0
    *My Web Search Plugin Stub for 32-bit Windows
    *Google Updater pluginhttp://pack.google.com/
    *Google Update
    *Next Generation Java Plug-in 1.6.0_20 for Mozilla browsers
    *Npdsplay dll

    * If the menu bar is hidden then press and hold the Alt key down, that should make the Menu bar appear (Firefox 3.6 on Windows) (see [[Menu bar is missing]]).
    * Make sure that you have the ''Navigation Toolbar'' and other toolbars visible: View > Toolbars .
    * If items are missing then see if you can find them in the View > Toolbars > Customize window.
    * If you see the item in the Customize window then drag it back from the Customize window to the Navigation toolbar.
    * If you do not see that item then click the Restore Default Set button in the View > Toolbars > Customize window.
    See also [[Back and forward or other toolbar buttons are missing]] and [[Navigation Toolbar items]]
    See http://kb.mozillazine.org/Toolbar_customization

  • I'm always losing all of my music and get a lot of apps that i don't need when i plug my i4 into my mac. I only ticked the box 'Manually manage music and videos' but it's always syncing itself. How can i prevent this? I don't want to put bacPlease Help!!!

    I'm always losing all of my music and get a lot of apps that i don't need when i plug my i4 into my mac. I only ticked the box 'Manually manage music and videos' but it's always syncing itself. How can i prevent this? I don't want to put back 1500 any more because of this. Please Help!!!

    I'm always losing all of my music and get a lot of apps that i don't need when i plug my i4 into my mac. I only ticked the box 'Manually manage music and videos' but it's always syncing itself. How can i prevent this? I don't want to put back 1500 any more because of this. Please Help!!!

  • My iphone is on recovery mode and i can´t turn on it, when i try to recover it from itunes i get: "unknown error (36), i´ve tried to do lot of things but i can´t  solve my problem. please help!!

    my iphone is on recovery mode and i can´t turn on it, when i try to recover it from itunes i get: unknown error (36), i´ve tried to do lot of things but i can´t solve my problem. please help!!

    Hi, i had the same problem. Try to find the file "apple" or "itunes" don't know it anymore exactly. Ahm well you need to delet any information or just plug in your iphone into an other computer. important is that your iphone never has been pluged in this computer before. This was what i did, and it worked!

  • I've tried everything I can think of to get my Iphone 4S to play albums like an Ipod does.  All it ever does is play the songs but not the albums in alphabetical order.  I used to think I was reasonably intelligent until I butted heads with this phone.

    I've tried everything I can think of to get my Iphone 4S to play albums like an Ipod does.  All it ever does is play the songs but not the albums in alphabetical order.  I used to think I was reasonably intelligent until I butted heads with this phone.

    Yes i've tried all of that. I've turned it all the way on and off and erased all of my music and put it back on and nothing works. And with the breaking up CDs and putting into compilation categories i have already fixed all of that stuff. It's fine it just doesn't show up in the list of artists. I can find the album in the songs category and the albums category it's just it doesn't show tha name of the artist. All of the other albums that i downloaded before i updated my itunes to th most recent update are fine. It's just the two that i downloaded afterwards. Thanks for trying though.

  • I have suddenly been getting a lot of fraud emails.  Does anyone know how to set up blocks?

    Hello,
    I have been suddenly getting tons of fraud emails.  This has never been a problem in my mack mail in the past. Does anyone know how to set up blocks?  I have searched through preferences but have not been able to find any way to do it.  Bounce is of no use as these emails are not "respondable".
    Gabrielle

    Hi Gabrielle,
    If you're using Mail, open Mail > Mail menu > Preferences > Rules > Add Rule > set the parameters you want.

  • A website I frequently visit will no longer come up. Safaris says that my connection has been lost but it hasn't. I even get emails from the website but I still can't get on it. Why would it all of a sudden do this?

    A website I frequently visit will no longer come up. Safaris says that my connection has been lost but it hasn't. I even get emails from the website but I still can't get on it. Why would it all of a sudden do this?

    The reason, I included the annotation that I'd upgraded my Itunes, (On my Computer) is B/C in many forums - the very first question, *HELPERS* ask, is. "Do you have the latest version of Itunes downloaded on your computer." I wanted to knock out any obvious replies.
    Now-  "DO YOU have any idea,"... how your UNHELPFUL remarks, do absolutely nothing but hurt others that might not have the EXPERIENCE you have? How do you expect people to know things without asking questions? Whew! RUDE!!
    Message was edited by: Apple I0S Help Team

  • Cannot get Spamassassint o move spam message  + add header.

    Hello!
    I want to move SPAM positive messages to SPAM folder and add header to spam messages. At this moment, SPAM-TEST header is added only to non-spam messages. SPAM positive messages ARE moved to SPAM folder, but the do not contain Spam-Test header.
    my option.dat file looks like:
    spamfilter1_library=/opt/sun/comms/messaging/lib/libspamass.so
    spamfilter1_config_file=/var/opt/sun/comms/messaging/config/spamassassin.opt
    spamfilter1_optional=1
    spamfilter1_string_action=data:, \
    require ["spamtest","relational","comparator-i;ascii-numeric","fileinto","addheader"]; \
    spamadjust "$U"; addheader "Spam-Test4: $U"; \
    if spamtest :value "ge" :comparator "i;ascii-numeric" "8" {fileinto "SPAM";} \
    else {keep;}
    What I have missed up? Please, give advice, as I am stucked with it :(

    This problem was discussed a few days ago, refer here:
    http://forums.sun.com/thread.jspa?threadID=5367487
    Regards,
    Shane.

  • D/l the new firefox / pop up blocked is set, but still getting a lot of them /did not have this with old firefox

    I never had problems with old firefox d/l the new one and getting a lot of pop up"s. I've checked my setting and them seem to be in order
    == This happened ==
    Every time Firefox opened
    == d/l new version

    i just updated Firefox today. I never had pop-ups. Today I have tons! 5 on each page i go to! i went to File/preferences; content; block pop-ups, and, indeed, that was already checked.
    I am overwhelmed by the amount of pop ups I am getting. Help, please.
    Thank you! Love you!

Maybe you are looking for