About a month ago, there was a discussion on the list about how spammers specifically target secondary MX records. After reading I verified that indeed 99% of the mail that flowed through my store-and-forward secondary mail server was spam. So, I removed the second MX record from my DNS zone, but did not actually decommission the server itself.

The interesting thing is that now, about a month later, I'm still seeing spam going to that server! I wonder if the spammers have cached the old MX entry or if they have some database of mail server addresses and what domains they will accept email for.

Reply via email to