I doubt a phisher got into your email server. If they ACTUALLY DID, then the first step is to make sure your server is secure. You'll have to hire a security expert to nail this down.
Next, is this a server you own or is this a shared email server at an ISP? Maybe it's the ISP's IP address that is blocked. If so, change IP addresses. Move your email to another server or another ISP.
If you are a company of any size, I strongly recommend outsourcing email to a professional secure organization.
