I have never seen these domains and I have no affiliation with them. Is this domain relaying mail through me?
10:25 01:06 SMTP-(000000D6) >MAIL FROM:<[EMAIL PROTECTED]>
10:25 01:06 SMTP-(000000D6) 250 2.1.0 <[EMAIL PROTECTED]>... Sender ok
10:25 01:06 SMTP-(000000D6) >RCPT To:<[EMAIL PROTECTED]>
10:25 01:06 SMTP-(000000D6) 250 2.1.5 <[EMAIL PROTECTED]>... Recipient ok
10:25 01:06 SMTP-(000000D6) >DATA
10:25 01:06 SMTP-(000000D6) 354 Enter mail, end with "." on a line by itself
10:25 01:06 SMTP-(000000D6) 50 2.0.0 e9P56l620127 Message accepted for delivery
10:25 01:07 SMTP-(000000D6) rdeliver blackvault.com [EMAIL PROTECTED] (1) <[EMAIL PROTECTED]> 4544
10:25 01:07 SMTP-(000000D6) >QUIT
Depends. Do you use relay for addresses and have disable SMTP Auth UNchecked? If so, then it is extremely likely that one of your users is actually [EMAIL PROTECTED] You can verify this by checking the IP address in the EHLO/HELO for that message. If it's an address valid for your relay for addresses setting then there is no problem. If it's not in your relay address range, there should be a line that reads as follows:
Authenticated username, session treated as local.
Of course, if you aren't using relay for addresses and UNchecked disable SMTP Auth, then all bets are off and you have an open relay.
Programmer/LAN Technician
Central Valley Water
[EMAIL PROTECTED] Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
