There are several things to check here:
1. Make certain you have SETTINGS ===> PROTOCOL SETTINGS ===> SMTP IN set to ALLOW RELAY = NOBODY
2, Make certain that all of your hosted domains are set to REQUIRE SMTP AUTHENTICATION under DOMAIN NAME ===> TECHNICAL:
3, Make certain your SMTP LOGS are set to DETAILED and then search for the e-mail address which is being spoofed in the SMTP LOGS. Validate those which are found against the headers from the messages.
4. If the account is running on a desktop, run a virus scan on the user's computer using HOUSECALL from TREND MICRO. Make certain you scan the entire machine and allow several hours for the scan to run. If there are viruses, it will find them and remove them.
5. Make certain the user's machine's IP ADDRESS is not SMTP BYPASSED or WHITELISTED. There is no reason to every whitelist an IP address any longer. It's a backdoor waiting to be found by hackers and it will be found - it's only a question of time.
Bruce Barnes
ChicagoNetTech Inc
brucecnt@comcast.net
Phonr: (773) 491-9019
Phone: (224) 444-0169
E-Mail and DNS Security Specialist
Network Security Specialist
Customer Service Portal: https://portal.chicagonettech.com
Website: https://www.ChicagoNetTech.com
Security Blog: http://networkbastion.blogspot.com/
Web and E-Mail Hosting, E-Mail Security and Consulting