I'm getting Advanced Threat Protection warnings from my UTM. The server mentioned in the errors is one of my DNS servers.
Looking through the DNS logs on the server I find that the box making the DNS request is my email server and the DNS record is mail.replyback.com.
Looking on the email server, sure enough I have an email in a queue that's trying to go to that server.
How do I fix the problem?
This thread was automatically locked due to age.