I noticed a rather serious problem today:
My system's set up to block illegitimate mail. I demand authentication to relay and I greywall, but today a piece of spam came through with one legitimate address for a local user, and about 12 users on other systems in the CC/BCC fields. Because one user was legit the message was accepted by Mercury, processed, and 12 messages forwarded to other systems.
This strikes me as a rather serious security hole, and I really don't know how to stop it. Any suggestions?