Following relevant policies and procedures of your organization, review all information (such as mail headers and system log files) related to the spoofed email.
Examine tcp_wrapper, ident, and sendmail logs to obtain information on the origin of the spoofed email.
The header of the email message often contains a complete history of the "hops" the message has taken to reach its destination. Information in the headers (such as the "Received:" and "Message-ID" information), in conjunction with your mail delivery logs, should help you to determine how the email reached your system.
If your mail reader does not allow you to review these headers, check the ASCII file that contains the original message.
NOTE: Some of the header information may be spoofed; and if the abuser connected directly to the SMTP port on your system, it may not be possible for you to identify the source of the activity.