About 2 weeks ago we switched our firewall, the thing we didn't know about this new firewall (managed solution) was that it was performing NAT on incoming packets, so the traffic appeared to be from our "trusted network". now the service provider is asking from some of the email headers for the messages that were being sent.

The messages in question were not being sent, or received by mailboxes in my domain so I don't have an actual message. I did write down some of the domain names the messages were being sent from while this was going on.

My question is what logs should I be looking at to find information about the messages that were sent?