Finished the first MVP which can handle basic analytics and blacklisting.
Updated our servers to use MailMum blacklist instead of internal cidr_map based blacklist directly on servers. By this change we got a lot of data which gained a lot of insights regarding internal mail traffic of our servers.
As we expected a lot (40-60%) of blacklisted hosts and networks from our manually built blacklist are not relevant anymore or never hit our servers again. This matched the insights we built based on our email server logs.
As the analytics also showed us, we could predict spammy hosts by their traffic peaks and especially networks by their well distributed delivery behaviour.
Identifying on spam and attacks specialized providers became a game changer too. We could see them, blacklist and monitor their action through different data centers around the world. A first "can be reputation" idea came up.