First line of defence is to add *@mydomain.com to SMTP -> Antispam -> Blacklisted Address Patterns. This will prevent a fake mailer to send e-mail outside your company as a user@mydomain.com in the FROM field.
↧