@intelisense
Hello, thank you for your answer and sorry for the late reply.
I took some time analyzing my SMTP server logs, and it contains 100% legit outgoing traffic. And no successful SSH connection for weeks on the server so it can’t have been erased.
u/voracity confirms my thoughts as well. I think the issue is outside and unrelated to my server. And the e-mail address in question seems to have leaked from several places according to haveibeenpwned (the password is safe though).
Hi, thank you for the answer, and sorry for the late reply :( …
I analysed the logs thoroughly, and I can confirm my SMTP server hasn’t sent any email aside the legitimate ones.
And u/voracitude 's answer confirmed my thoughts, being that the emails were sent from somewhere else.
I don’t think it’s that much unusual to use a “small” domain for spoofing: SMEs are “easy targets” usually, and if the recipient’s anti-spam isn’t configured properly then the attackers could benefit from a domain which may be small but has a good reputation.