Currently I have an LDAP to an Exchange 2016 Server and currently quarantine non-existent users (eventually block).
However if someone accidently makes a mistake with the email, ideally it would be best they get a notification that no such user exists - however this gives rise to spammers and possibly directory harvests from what I have read.
I understand that it is supposed to be sent from the Exchange, however using Verify Recipients (Yes 450) seems to get a a few issues whereby most emails verifies correctly, and then a very small proportion gets blocked in a recent incident whereby an email from a real sender gets blocked. So I had to disable Verify Senders and the emails were delviered successfully.
But then if I enable notification to Non-LDAP via PMG:
However if someone accidently makes a mistake with the email, ideally it would be best they get a notification that no such user exists - however this gives rise to spammers and possibly directory harvests from what I have read.
I understand that it is supposed to be sent from the Exchange, however using Verify Recipients (Yes 450) seems to get a a few issues whereby most emails verifies correctly, and then a very small proportion gets blocked in a recent incident whereby an email from a real sender gets blocked. So I had to disable Verify Senders and the emails were delviered successfully.
But then if I enable notification to Non-LDAP via PMG:
- How long will the reply email stay in PMG queue?
- Could this be used for backscatter attacks?