Internal Email Address Sending Spam?

I have received to emails from scan@ourdomain.com in the last week or so. The body of the emails are blank but there is an attachment. We don't have a scan@ourdomain email account internally so my guess is spammers are spoofing it. Is there a way that I can verify that by looking at something in Exchange or some other method?

8/22/2022 - Mon