We're setting up some Proofpoint demo boxes and using SMTP VRFY
callouts to our exim (4.20) relays to verify recipients. It appears
that when the LDAP server returns a DEFER, that the entire LDAP error
(including search string, bind dn and passwd) are passed back to the
Proofpoint box and nothing is logged by exim.
I can't exactly verify this yet, as the DEFERs are rather few and far
between and I can't go change the exim config without jumping through
bureaucratic hoops. We're going to narrow it down to one exim relay
(instead of 3 behind a load balancer) and then compare it to a 4.60
test box, but I thought I'd see if folks might have seen this before.