Hi all, I recently set up a virtual machine running SME server that is replacing our old Windows NT mail server. Essentially it's only running for my Dad's home business, and only has 3 mailboxes. I believe I've set it up as secure as I can (through the web interface) and the spam filtering was working fantastically, however a couple of weeks after setting it up, we are now receiving ALOT of automated replies saying our emails can't be delivered (emails that we didn't even send). I originally thought that it could've been someone spoofing our domain and having the bounce-back come to us, but I also noticed that the mail server runs super slow when exposed to the internet (when I close the ports and reboot it, it's fine), which leads me to believe that it's getting backed up with loads of spam to redirect. The server specs are very decent, and I've allocated about 256mb RAM to the virtual machine, which should be plenty. I'm not real experienced with Linux, but I am learning, and I do have a bit of experience administering our old mail server.
Is it possible that somehow our SME Server is being used as an open relay by spammers? I would've thought such options would be disabled by default. Additionally, how would I go about further securing our server (going above and beyond the web interface)?
Our server is running behind a firewall, with only the SMTP port (25) and POP3 port (110) forwarded to the SME server.