As System Administrator > Manage > Spool Dashboard > Top Outbound IP Addresses
I'm curious where this list of IP addresses comes from. I noticed in the list this morning an address of 192.168.1.114 having sent 8 messages in the last 24 hours; 6 in the last hour. We do not use that block of addresses anywhere within our network, and that address is not a publicly-routable address. In searching the SMTP logs, the only references that I find to that address are in the EHLO handshake; the actual IP address is 220.127.116.11. Is this a bug?
It seems like the actual IP address of 18.104.22.168 should be considered the Outbound IP Address, rather than anything provided via the EHLO handshake, which may not have anything to do with the actual IP address being used.
In looking at the log, I'm guessing that this is the internal IP address of the user's computer, but it's not the public address that they likely NATed behind. Displaying a private address in this list isn't particularly helpful.
Has anyone else seen this behavior?