Quoting Florin Iucha (florin at iucha.net):
> So somebody broke into enchanter.real-time.com? Or is spoofing it?

Pretty sure they are spoofing it. Enchanter is pretty well locked down.

Feb  4 20:17:37 enchanter sendmail[32026]: g152HWY32026:
from=<dtherman at real-time.com>, size=111736, class=0, nrcpts=4,
msgid=<200202050217.g152HWY32026 at enchanter.real-time.com>, bodytype=8BITMIME,
proto=SMTP, daemon=MTA, relay=dsherman-rt-dsl.real-time.com [208.20.203.226] 

Something is very whacked on your network.

How can the dsl router be an smtp relay?

None-the-less:

% telnet 208.20.203.226 25
Trying 208.20.203.226...
Connected to 208.20.203.226.
Escape character is '^]'.
220 sildara.dyndns.org ESMTP Postfix
quit
221 Bye

Looks like maybe your DSL router got compromised and they setup SMTP port
forwarding SMTP traffic?

Or you got NAT running on the DSL router with port forwarding?



-- 
Minneapolis St. Paul Twin Cities MN        | Phone : (952)943-8700
http://www.mn-linux.org Minnesota Linux    | Fax   : (952)943-8500
Key fingerprint =  6C E9 51 4F D5 3E 4C 66 62 A9 10 E5 35 85 39 D9