Lots of smtp connections reported by Logwatch?

I get a security report from logwatch everyday, and of course, always browse through it. Recently, I noticed that I got quite a sh*tload of connections from 1 particular ip, about 4 hops from me (traceroute).

I'm pretty sure spammers can't relay through my server, but don't know what to think of these connections (200 times more than the other IPs).

Any toughts on that?

 

 

 

 

Top