I installed a mail server in aapanel, set up DNS, and was using it well, but one day I noticed an abnormal increase in email sending volume.
As a result of analyzing the email report sent by Google, it was confirmed that there were several attempts to send emails to an IP that I did not know, rather than my server IP. It is even said that one of them was actually sent. Please tell me what to do in this case. thank you!

<feedback>
<report_metadata>
<org_name>google.com</org_name>
<email>noreply-dmarc-support@google.com</email>
<extra_contact_info>https://support.google.com/a/answer/123456</extra_contact_info>
<report_id>123456</report_id>
<date_range>
<begin>1739059200</begin>
<end>1739145599</end>
</date_range>
</report_metadata>
<policy_published>
<domain>svsvo.com</domain>
<adkim>r</adkim>
<aspf>r</aspf>
<p>quarantine</p>
<sp>quarantine</sp>
<pct>100</pct>
<np>quarantine</np>
</policy_published>
<record>
<row>
<source_ip>198.135.48.73</source_ip>
<count>1</count>
<policy_evaluated>
<disposition>none</disposition>
<dkim>fail</dkim>
<spf>fail</spf>
<reason>
<type>forwarded</type>
<comment>looks forwarded, not quarantined for DMARC</comment>
</reason>
</policy_evaluated>
</row>
<identifiers>
<header_from>xirudg.svsvo.com</header_from>
</identifiers>
<auth_results>
<dkim>
<domain>xirudg.svsvo.com</domain>
<result>fail</result>
<selector>050200</selector>
</dkim>
<spf>
<domain>ciel576.me</domain>
<result>pass</result>
</spf>
</auth_results>
</record>
<record>
<row>
<source_ip>198.135.48.73</source_ip>
<count>61</count>
<policy_evaluated>
<disposition>quarantine</disposition>
<dkim>fail</dkim>
<spf>fail</spf>
</policy_evaluated>
</row>
<identifiers>
<header_from>xirudg.svsvo.com</header_from>
</identifiers>
<auth_results>
<dkim>
<domain>xirudg.svsvo.com</domain>
<result>fail</result>
<selector>050200</selector>
</dkim>
<spf>
<domain>ciel576.me</domain>
<result>pass</result>
</spf>
</auth_results>
</record>
</feedback>