I am seeing a lot of emails being denied in the outgoing proxy but cannot see the origins of the traffic. Also I am seeing stuff like this:
ostfix/smtpd[11648]: NOQUEUE: reject: RCPT from s208-180-21-173.bcstcmta02.clsttx.tl.sta.suddenlink.net[208. 180.21.173]: 554 5.7.1 <
therichsheickc@yahoo.com>: Relay access denied; from=<
test@live.com> to=<
therichsheickc@yahoo.com> proto=ESMTP helo=<[192.168.2.33]>
...which tells me one of my office machines is hacked and being used as a junk mail relay. But it does not tell me even the ip address of the source. Can anyone tell me how to trace this?