First have a quick look here:
http://www.scalix.com/wiki/index.php?title=HowTos/ScalixSecurity
then you might want to check if you are an open relay:
http://www.checkor.com/
Also you might harden your users passwords as if you are not an open relay then most probably one of your mail accounts is compromised.
If not any of the above start looking for trojans on your mail server. To buy yourself some time you might consider geo-blocking hinet unless you do business with Taiwan (http://www.theillien.com/Sys_Admin_v12/html/v14/i11/a3.htm).
It's a rough world out there...