I started receiving a bunch of bounced emails to one of my email accounts.. Apparently some russian spammer is sending out spams using my email as the "reply to" address. So all the bounced spam comes back to me. I am wondering if they are somehow using my server to send these mails. But I'm not sure how to check what emails are exactly outgoing from my smtp server. How can I check this? Furthermore, how can I disable this service, or password protect it? Thanks!
They most probably dont use your server. It is normal that spammers are using email addresses from other unrelated poeple as sender address, this does not mean that the emails are send from the server that hosts the email address normally. You can not do anything against this. If you want to check that your server is not sending these mails, have a look at the mail log. If you get there many (most likely hundreds) of outgoing mails per minute, then your server is sending the spam. But it is very unlikely as I never saw that spammers are using addresses from the server they are sending from as sender address.
If you have their domain name or ip address, try looking up the abuse email address of their ISP. Probably won't fix anything quick, but at least its a step in the right direction.