Running SME 6.0.1 with Spamassassin, ClamAV, and mailfront mailblocking. This server is configured in server only mode, it's only job is to filter email and pass it on to an internal Exchange server for delivery.
Problem: twice within the past 2 months this server's remote mail queue has gotten clogged with tens of thousands of outgoing emails addressed to the sayclub.com domain. There are so many there (over 20000) that SME's email server comes to a screeching halt. If I pull SME out of the network and send all incoming mail directly to the exchange server, everything works again. Plus, the exchange server's outgoing logs show no traffic going to the sayclub.com domain. So it appears that this traffic is either originating with the SME server or is somehow being relayed through it.
The last time this happened I formatted the drives and reinstalled SME totally. It has now been running for only 2 weeks and again has this problem. I am looking for a way to find (probably from the command line) all messages in the remote queues that are addressed to the sayclub.com domain and then delete them. Does anyone know how to do this?
Also, does anyone have a clue as to what is going on with this server? I could give someone remote access to it if you want to poke around. And, if you can spot the problem and get it fixed I will gladly pay for your expertise.
Joe