John Andersen wrote: >On Monday 20 November 2006 15:08, Rick Macdougall wrote: > > >>It's possible that they could send it all twice but I've never seen it. >> Remember that some unbelievable number of infected Windows clients are >>the main source of spam and it would just be too much trouble for the >>spammer to try every address twice after a 15 minute interval. >> >> > >Oh come on! It costs the spammer NOTHING to make that adjustment >to his bot net. Its someone else's bandwidth, and someone else's >cpu cycles. > >They are reading this list and planning the changes already. > > >
If the graylist time is 15 minutes (for instance), and someone reports them fairly soon after they start up... and their ISP is quick to shut them down (cough, cough) then we're managed to severely limit how many sites they hit before they get shut down. Of course, graylisting a larger value (2 hours) for totally unknown correspondents would be more effective. -Philip