There's a few things that can allow that.. Users can add personas to their accounts right in the web client with whatever address they want if the checkbox is checked in the admin console for their user. They can also do the same from their mail clients. There's also the possibility that some server in your trusted networks is using it as a relay. (there are plenty more possibilities)
Most importantly, you'll want to make sure you're not an open relay to the world. I'd recommend
this tool.