Does it make sense to track how many valid & invalid addresses are provided for a message, and allow a threshold to consider that spam?
Although not as frequently as in the past, I still see messages coming in with dictionary attacks, e.g., RCPT <[EMAIL PROTECTED]> RCPT <[EMAIL PROTECTED]> RCPT <[EMAIL PROTECTED]> RCPT <[EMAIL PROTECTED]> and perhaps one of those happens to have a hit. It might be nice to reject it because all of the others failed. --- Noel --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]