I don't see any SPF or DMARC checking in the headers on inbound email and I am currently researching it.
Amavis does not check SPF or DMARC itself, but SpamAssassin will do it, if configured.
2024-11-05T16:50:43.961525+00:00 mail-www amavis[3676918]: (3676918-01) Passed CLEAN {RelayedOpenRelay}, [34.209.113.130]:51018 [34.209.113.130] <[email protected]> -> <[email protected]>, ...
You need to declare howitts.co.uk as one of yours (on Debian see conf.d/05-domain_id) to get rid of OpenRelay.
