Michael, > Perhaps a better approach to blocking is the RECENT target in netfilter. > Parsing the log file a script could easily add misbehaving IP addresses. Thanks, but it's not really an option for me. I don't want strict blacklisting, I just want a score bonus for bad senders. Patrick