So I set the smtp_accept_max_per_host to '20' but it didn't work. Also tried the smtp_accept_max to 20 but that didn't work either. It seems like absolutely nothing from Exim is working against dictionary attacks. This is crazy. Still getting exactly 100 messages on each attack, and something is obviously blocking or limiting them to 100, but I don't understand what it is. The only thing I can imagine is that the attacker is only sending 100 at a time, but that really defeats the purpose of sending a dictionary attack.
we are having this issue since some days ago.. this has never happened, and we haven't made any change. but since some days, we are seeing 400k to 1million -remote- mail on every server. and it's exactly the same as this thread.