On a machine just after 5.7 bumped to get spamd TLS support where changes to spamd have been minimal since (I have tested the compat mode diff with no effect).
I've had reports of mails not coming through and they have been quite tricky to find (traffic logs of known incoming mail) as they do not hit the spamd logs (except as ip disconnected after 19 seconds) or show up in spamdb as the connection fails early on before getting to the mail addresses. This only seem to affect microsoft/exchange who don't monitor postmaster@. The intermediate is correctly loaded though it wasn't originally. The microsoft end receives a QUEUE.Expired failure message that states it's not their fault so don't contact (arrogant #@!*s), though using hotmail.com gives even less information (couldn't connect). I created an account at hotmail.com and found that removing the -K and -C flags when starting spamd solves the issue but I would prefer to minimise the plain text on the wire if possible, secure or not (No DANE yet). Once past spamd the exchange TLS works with opensmtpd TIA for any help/info. I shall try 5.8 when released but I don't expect it to fix the issue personally? -- KISSIS - Keep It Simple So It's Securable