You can see who is open the connections in 25 port for example like: netstat -an | grep 25 and make block for the IP which make many connections on your firewall