Hi all, That recent spammer sent from this machine: 153-149-25-99.compute.jp-e1.cloudn-service.com This helped me discover an long-standing bug in my Exim4 mail server configuration that I finally discovered thanks to this intrusion. Now we can tell from the host name that it's likely a subscriber line (that shouldn't be sending SMTP to us directly). I have had a rule for a long time in my Exim4 configuration to reject addresses. Unfortunately, that rule included multiple pattern matches, which were separated using the wrong character: hosts = pattern1 | pattern2 | pattern3 ... rather than the correct colon character: hosts = pattern1 : pattern2 : pattern3 ... Oops!