在缺省情况下Anonymous user权限组有下面的权限:
要阻止别冒充域名发送邮件,可以使用下面的方法来解决:
方法一:
1. 在Exchange中心传输服务器上,运行ADSIEDIT.msc.
2. 浏览定位到Configuration->Services->Microsoft Exchange->First Organization->Adminstrative Groups->Exchange Administrative Group ->Servers->server_name->Protocols->SMTP Receive Connector
3. 右击Default Receive Connector并切换到Security栏,点击选中Anonymous Logon.
4. 在下面的列表中点击选中 Accept Authoritative Domain Sender右边的Deny.
5. 重启Microsoft Transport services服务.
方法二:
1.在PowerShell下输入以下命令:
Get-ReceiveConnector “Default SRV12-01″ | Get-ADPermission -user “NT AUTHORITY\Anonymous Logon” | where {$_.ExtendedRights -like “ms-exch-smtp-accept-authoritative-domain-sender”} | Remove-ADPermission
2. 重启Microsoft Exchange 传输服务。