@rozzin that sounds like the evolution of spam origin analysis: first, all Received: headers were checked; but then it was seen that those c[…]