Spammers could be spoofing your email.
This message is coming from ConfigServer Firewall (CSF). This specific alert is generated when an email account uses SMTP AUTH to send emails at a rate that exceeds the configured limits.
- Ensure that the SPF record is set.
- Change the email password (or delete the email account if not used)
A CONFIG_SERVER AUTHRELAY Alert from ConfigServer Firewall (CSF) and Login Failure Daemon (LFD) indicates an email account is using SMTP AUTH (authenticating with a username and password) to send a large volume of emails too quickly, likely due to a compromised password or a legitimate script sending too many messages.