Here's what an SMTP log will show when someone authenticates:
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 220 securemail.chicagonettech.com (<=== NAME OF MX SERVER ACCEPTING MESSAGE)
Mon, 16 Mar 2015 14:15:24 +0000 UTC | SmarterMail Enterprise 13.3.5535.16496 (Day, Date, Month, Year and Time - set in UTC or ZULU time zone to assist in troubleshooting so all times will be the same, no matter what time zone the server sending or receiving the e-mail message is in - this can be configured by the SmarterMail server operator)
[2015.03.16] 09:15:24 [173.165.112.149][48348077]
connected at 3/16/2015 9:15:24 AM (date and time of connection in LOCAL SERVER TIME)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] cmd: EHLO
WORKSTATION (shows name of workstation or device sending message)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 250-securemail.chicagonettech.com Hello [173.165.112.149]
250-SIZE 52428800250-AUTH CRAM-MD5250-STARTTLS250-8BITMIME250 OK
[2015.03.16] 09:15:24 [173.165.112.149][48348077] cmd: STARTTLS
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 220 Start TLS negotiation (TLS encryption negotiation for consecction - requires SmarterMail ENTERPRISE, an SSL certificate and using IIS)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] cmd:
WORKSTATION (shows name of workstation of device sending message)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 250-securemail.chicagonettech.com Hello [173.165.112.149]250-SIZE 52428800250-AUTH LOGIN CRAM-MD5250-8BITMIME250 OK
[2015.03.16] 09:15:24 [173.165.112.149][48348077] cmd: AUTH LOGIN
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 334 VXNlcm5hbWU6
[2015.03.16] 09:15:24 [173.165.112.149][48348077]
Authenticating as bbarnes@chicagonettech.com (this is the e-mail addres used to log into the SmarterMail server)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 334 UGFzc3dvcmQ6
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 235
Authentication successful (the sender used a valid password and the process will continue)
[2015.03.16] 09:15:24 [173.165.112.149][48348077]
Authenticated as bbarnes@chicagonettech.com (this is who sent the message)
[2015.03.16] 09:15:24 [173.165.112.149][48348077]
cmd: MAIL FROM: <bbarnes@chicagonettech.com> (this is the REPLY TO address contained in the message - should almost always match MAIL FROM address)
[2015.03.16] 09:15:24 [173.165.112.149][48348077]
rsp: 250 OK <bbarnes@chicagonettech.com> Sender ok
(the sender is OK and authorized to send via this mail server)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] cmd:
RCPT TO: <REDACTED@comcast.net> (who the message is being sent to)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 250 OK
<REDACTED@comcast.net> Recipient ok (we don't have that e-mail address in any deny list, so it's OK to accept the message)
[2015.03.16] 09:15:24 [173.165.112.149][48348077] cmd: DATA
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 354 Start mail input; end with <CRLF>.<CRLF>
[2015.03.16] 09:15:24 [173.165.112.149][48348077] rsp: 250 OK
[2015.03.16] 09:15:24 [173.165.112.149][48348077] Data transfer succeeded, writing mail to 71114155.eml
[2015.03.16] 09:15:26 [173.165.112.149][48348077] cmd: QUIT
[2015.03.16] 09:15:26 [173.165.112.149][48348077] rsp: 221 Service closing transmission channel
[2015.03.16] 09:15:26 [173.165.112.149][48348077] disconnected at 3/16/2015 9:15:26 AM
Unless you see something like that in your log, the message probably did not originate from your SmarterMail server.
Bruce Barnes
ChicagoNetTech Inc
brucecnt@comcast.net
Phonr: (773) 491-9019
Phone: (224) 444-0169
E-Mail and DNS Security Specialist
Network Security Specialist
Customer Service Portal: https://portal.chicagonettech.com
Website: https://www.ChicagoNetTech.com
Security Blog: http://networkbastion.blogspot.com/
Web and E-Mail Hosting, E-Mail Security and Consulting