I'm not sure about that specific alert but does the source indicate a client, or perhaps a mail server on your network? I typically use the source and destination to try to start running captures to gain more insight into what is going on.
Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.