Be aware there may have been some innocent victims of that. Some messages from non-compromised accounts may still be sitting in the old queue. i would purge the old queue of messages from the compromised account, and see what is left.
find and grep will be your friends here.
agreed but in my case I'm happy if a few genuine outbounds were lost then so be it.
As a side note or question, can something like fail2ban be included by default but with looser settings than default. Even better a fail2ban menu in server manager with disabled, low, medium, high settings etc?