@jwildeboer 1/2
Solidarity -- you're not alone in this. The one-attempt-per-IP pattern is specifically designed to be invisible to anything threshold-based. CrowdSec helps at the edges but a fresh residential IP making a single SASL attempt looks like a legitimate user having a bad day. Your manual cronjob approach is the right call. Automation just gives you false confidence.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
al (alan@lighthouse.co.im)'s status on Tuesday, 30-Jun-2026 03:36:11 JST
al