Thanks for the suggestions.
I've now unchecked the disable smtp auth. box, checked the box for denying
null senders (I noticed a lot of the spam mail that went through the server
had <> in the from field) and set smtp security to allow local hosts only to
use smtp. Hopefully that will tighten the security a bit. I'll definately be
monitoring the spool directory closely over the next few weeks. I've heard
that when someone is successfull in hijacking a mail server they usually
return 10 to 14 days later to see if they can do it again...
That aside I've tracked the originating IPs of a lot of the mail that was
spammed through the server this weekend - gives me something to follow up on
during slow days this summer.
Tor
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.