to deliver mail. Hosts that *aren't* on the list have their initial connections dropped. If they connect again to try to deliver a little later, then they're allowed to send and they're added to the whitelist.

They're not dropped, they're given a _valid_ "temporarily unavailable"
SMTP response. Legit MTAs should retry, although at least one of the
big email providers had braindead config that treated "try again later"
as "explode like a zeppelin full pyromaniac of chainsmokers in a thunderstorm", at least a while ago. Spammers and the like tend to just
move on (for now) to easier pickings.

