I understand that. But we cannot necessarily get to a machine quickly enough to prevent the alerts from bringing the mail server down. I’m talking in the range of 50,000 alerts. Dropping everything and scrambling to find/disconnect/clean the infected machine before the mail server goes down is not an efficient means of operating. Any suggestions from users who have handled this would be appreciated. Thanks in advance.