(I know this is a bit off postfix, but not completely)
I'm running postfix as MTA on a machine with several CMS. Recently, there is a huge number of spam being sent from there, alas. When I scan the logs, all those come from 'root', meaning they don't come through port 25. I run OpenBSD with mini-sendmail, and now I wonder how I could find out from which CMS they are sent. Is there any chance to find out from postfix? I am afraid, not? If not, what else could I do?
Thanks, Uwe