Hi @josephgodwinke
i deleted everything in the log(took a copy before hand) and sent 1 email, this is everything
i found this in the log what you think it means
Found phishing fraud from http://http:/www.receiverdomain.com.au/ claiming to be www.receiverdomain.com.au in 6BDD9FFFFB.A7C10
log start here
Nov 22 18:13:48 ECM-Site-and-Email dovecot: imap-login: Login: user=daniel.collins@ecmindustrial.com.au, method=PLAIN, rip=my_ip, lip=rec_ip, mpid=899340, TLS, session=<+RvV6Qnu18E7ZPOW>
Nov 22 18:14:06 ECM-Site-and-Email postfix/smtps/smtpd[899351]: connect from ---.mel.static-ipl.aapt.com.au[myip]
Nov 22 18:14:07 ECM-Site-and-Email postfix/smtps/smtpd[899351]: 6BDD9FFFFB: client=---.mel.static-ipl.aapt.com.au[my_ip], sasl_method=PLAIN, sasl_username=@ecmindustrial.com.au
Nov 22 18:14:07 ECM-Site-and-Email postfix/cleanup[899355]: 6BDD9FFFFB: hold: header Received: from HomeComp (---0.mel.static-ipl.aapt.com.au [my_ip])??(Authenticated sender: daniel.collins@ecmindustrial.com.au)??by ecmindustrial.com.au (Postfix) with ESMTPSA id 6BD from ---**.mel.static-ipl.aapt.com.au[my_ip]; from=daniel.collins@ecmindustrial.com.au to=JohnSmith@Reciverdomain.com.au proto=ESMTP helo=
Nov 22 18:14:07 ECM-Site-and-Email postfix/cleanup[899355]: 6BDD9FFFFB: message-id=055d01d8fe42$03116d40$093447c0$@ecmindustrial.com.au
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: New Batch: Scanning 1 messages, 608607 bytes
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: Virus and Content Scanning: Starting
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: Message 6BDD9FFFFB.A7C10 from my_ip (daniel.collins@ecmindustrial.com.au) to receiverdomain.com.au is too big for spam checks (608607 > 200000 bytes)
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[899369]: Found phishing fraud from http://http:/www.receiverdomain.com.au/ claiming to be www.receiverdomain.com.au in 6BDD9FFFFB.A7C10
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: Requeue: 6BDD9FFFFB.A7C10 to 03EBB100003
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: Uninfected: Delivered 1 messages
Nov 22 18:14:09 ECM-Site-and-Email postfix/qmgr[1576]: 03EBB100003: from=daniel.collins@ecmindustrial.com.au, size=607002, nrcpt=1 (queue active)
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: Deleted 1 messages from processing-database
Nov 22 18:14:09 ECM-Site-and-Email MailScanner[898781]: MailWatch: Logging message 6BDD9FFFFB.A7C10 to SQL
Nov 22 18:14:09 ECM-Site-and-Email MailWatch SQL[898787]: 6BDD9FFFFB.A7C10: Logged to MailWatch SQL
Nov 22 18:14:09 ECM-Site-and-Email postfix/smtp[899370]: 03EBB100003: to=JohnSmith@reciverdomain.com.au, relay=REDACTED-mx1.firstcloudsecurity.net[rec_ip]:25, delay=2.3, delays=2.1/0.01/0.15/0.09, dsn=5.0.0, status=bounced (host REDACTED-mx1.firstcloudsecurity.net[rec_ip] said: 550 #5.7.1 Your access to submit messages to this e-mail system has been rejected. (in reply to DATA command))
Nov 22 18:14:09 ECM-Site-and-Email postfix/cleanup[899355]: B2274100009: message-id=20221122071409.B2274100009@ecmindustrial.com.au
Nov 22 18:14:09 ECM-Site-and-Email postfix/bounce[899371]: 03EBB100003: sender non-delivery notification: B2274100009
Nov 22 18:14:09 ECM-Site-and-Email postfix/qmgr[1576]: B2274100009: from=<>, size=4001, nrcpt=1 (queue active)
Nov 22 18:14:09 ECM-Site-and-Email postfix/qmgr[1576]: 03EBB100003: removed
Nov 22 18:14:09 ECM-Site-and-Email postfix/pipe[899372]: B2274100009: to=daniel.collins@ecmindustrial.com.au, relay=dovecot, delay=0.08, delays=0.05/0.01/0/0.02, dsn=2.0.0, status=sent (delivered via dovecot service)
Nov 22 18:14:09 ECM-Site-and-Email postfix/qmgr[1576]: B2274100009: removed
Nov 22 18:14:10 ECM-Site-and-Email postfix/smtps/smtpd[899351]: disconnect from 59-100-243-150.mel.static-ipl.aapt.com.au[59.100.243.150] ehlo=1 auth=1 mail=1 rcpt=1 data=1 quit=1 commands=6
Nov 22 18:14:11 ECM-Site-and-Email dovecot: imap-login: Login: user=admin@ecmindustrial.com.au, method=PLAIN, rip=MY_IP, lip=Server_IP, mpid=899375, TLS, session=<3eEt6wnu3sE7ZPOW>