Hey guys, I was looking at my firewall logs yesterday and noticed a big increase in my Firewall service logs. Started running it down and the logs shows a ton of DNS and SMTP traffic coming from my outbound relay. We'll wouldn't you know it, it wasnt' even the ISA firewall's fault :-) You might want to this out and disable sending NDRs. Fixed the problem for me. MAPILab.Com - Articles: http://www.mapilab.com/articles/ndr_spam_attack.htm HTH, Toml