Well... Port 135 is much more "attackable" than 443 so it makes it very hard to tell now you might have been compromised...

The question is "were you compromised"?

Did the email leave the exchange server or was it a totally internal email?
Did one of the recipients forward it outside the network, (check your logs - you have logs, right?)

The first thing you need to do is _confirm_ a compromise... Otherwise you will be chasing your tail all day for no reason....