Every single item of spam I receive through my pobox.com account has gone
through a relay listed in ORBS (
http://www.orbs.org/ ). So I like would to
scan all hops for IPs that are in the ORBS database. This doesn't at first
sight appear trivial--perhaps if exim had an ORBS lookup routine (along with
its dbm file, aliasfile, etc) it would be quite simple?
In the meantime, if Received: contains ".co.jp" or ".br" or ".es" seems to
work quite well *sigh*.
Thanks,
Paul
PS
http://pobox.com do an excellent job and are very responsive to spam
support queries. It's just their configuration only uses MAPS which seems to
not have as larger or as responsive a database as ORBS.