Hi,
What's the time resolution of ratelimit? Is a time of five seconds
resonable, or not really supported by the implementation?
I'm interested in detecting connection bursts, having noted that
one class of spammer (usually also zombie-farmed) makes three-to-six
connections close together. (They also have variable HELO names per IP,
and often but not always fail helo-verify).
Thanks,
Jeremy