I've checked my mainlog and the originating ip appears to be exactly the same as the email header; 67.228.245.121 Could it be ip spoofing? How would they do that? Or maybe exim is somehow accepting connections over udp? - I'm clutching at straws! Hoping someone can help me solve this. Thank you for the feedback so far.