Also, just as an FYI, i do network security in a completely different sector, but the attacks are usually the same. The "sneak forwarding" is a common targeted attack. More likely though, is the human element, an administrator paid to set things up. Systems are usually surprisingly secure. Almost every successful attack i see involves phishing or an inside job. Just as an fyi though, nmap is a powerful tool, and anyone can intercept and reconstruct any email that is sent over the internet if it is not pgp encrypted. i've done this for more than one client to prove the point.