Hmmm. Me be perplexed and need some other brain power. We see occasional spikes in activity shown in senderbase for our mailserver (14.x). Normally our mail server shows as 0.0 in email volume on Senderbase and this is expected given our low volume. However, occasionally Senderbase will show a big increase like 2500%.
I have been pouring over the smartermail logs, event logs, and sysmon logs (we are tracking sent/received port 25 and 465) and I can't find anything to explain a 2500% increase. Even wrote a utility to break the smarter mail smtp log apart by IP, AuthFailed, Greylisted, InboundMail, IPBlocks, NoSuchUser, OutboundMail, SpamBlocked, and Unknown (if it doesn't fit one of the others). The log data simply doesn't reflect these Senderbase increases.
I could go into a bunch of areas explaining our setup at this point but regardless of that it would show in the logs, right?
I'd be glad to provide more information and would love some other brain power to help me understand why Senderbase and the logs could be so different.