When spammers connect to a mailserver, they often just issue the commands bang bang bang, and don't wait for a response. I've read that raising the in_flow_delay to 5 seconds or so can cause spamming clients like this to fail, as they send their commands out of sync.
Anyone have any experience with implementing this method in a corporate environment? I really want to avoid false positives.
FYI I am getting 5000 or so spam connections that aren't blacklisted, about 200-300 messages get through the spam filters...