But would those be the IPs were emails are coming back from (say if someone
forged our domains in their spam) or would this be the IPs that are
connecting and trying to relay?

Unless you are running the adams.net, aain.com, abovenet.com, aaa.com, and aap.com domains, then they are relay attempts.


If they are from a spammer somewhere else that is forging a return address on your domain, the "RCPT TO:" line will be to a user of yours.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to