There are ISP's using dccm with enough incoming spam to regularly
generate a couple of hundred log files in a minute, not to mention 3
or 4 days.  Recent versions of dccproc and dccm have the strange,
optional values "[HMH]?name' for -l in an attempt to keep log file
directories from blowing up larger than Linux will tolerate.

I suspect ISPs are handling white list entries with a single, system
wide list.  I think they initially populate their white lists by running
dccm the rejections turned off and the logging threshold at or below
the future rejection threshold.  During this initial period, they watch
for legitimate bulk mail in the logs and white-list its senders

This mode clearly makes sense on a corporate gateway where users receive
only company mail and "company mail" is defined by the operators of
the gateway.  I'm surprised this mode works for ISPs selling to the
general public.  I would have expected a scheme like Dave Lugu's to be
required.  That a single, system-wide white list works for ISPs with
plenty of users may show how unhappy the general public is about spam.

