Seems like a single Spammer found my wip mail server. Sadly it doesn't yet support being misused as an open relay 🙃
But hey I just finished some basic user adding and password changing cli with a planned (wip) status command as well as adding auth to the endpoints. Allowing me to implement pieces to actually send messages without the fear of having an open relay :)