Now I ended up switcing to tls-require on port 25. I wonder how much spam that will take down! :)

Well, that's depressing.

On the spam front - requiring TLS apparently cuts off about 99% of spam (SpamAssassin is practically out of work), but we do get the occasional legit non-TLS connection and I'm having to switch back to optional TLS. :/

So TLS is 20 years old but they're (banks etc) still sending somewhat private info in plain text.

'twas fun while it lasted. :)

I'm going to start schooling them one by one.


