It has just been brought to my attention that postfix by default has: postconf | grep percent allow_percent_hack = no
... set to yes. argh I know at some point I set it to "no" in my standard config file, but when I just checked it wasn't there. I've corrected it in my file. Everybody should check all their postfix boxes __immediately__. AOL uses the percent hack to test open relay and will block mail from your IP if they find it. just add the line and "postfix reload" and check it with postconf Len
