Good morning Robert.
Thank you for the reply on this. To answer your question on the Admin log, I checked and all login attempts from their office IP were successful logins. At no point was there a bad login attempt happening. Plus with the DOS rule, this should really just be SMTP connections correct? Or does it look at POP and IMAP connections as well?
The rule is set as follows:
Detection Type: Denial of Service (DOS)
Service: SMTP
Time Frame: 2 minutes
Connections Before Block: 20
Time to Block: 5 minutes
So with that said, the way I see this is the rule should be paying attention to the SMTP service correct? Between the SMTP log and the Administrative log at no point did either log give us any indication there was a problem. One minute they are sending email just fine and then a few minutes later the log shows "421 server is busy". All emails are sent from their static IP at their office.