Gee, I wonder if this is a spam zombie
There were some attempts to send mail from from IP address 82.128.3.73, before I spotted the traffic and preemptively bunged the domain into the blacklist. A smtp conversation starts up with the caller identifying themselves with a HELO command, in the form HELO <hostname-or-meaningless-token>. It doesn't usually matter what the hostname-or-meaningless-token is, but when a site connects 10 times and gives 10 different homts, that tends to raise suspicions. And there are extra added suspicion points for the hostname looking like a dialup machine.
HELO helimore2874.com HELO ok62496.com HELO helimore2695.com HELO ab17c444.com HELO mrson2460.com HELO emztd2550.com HELO mrson2532.com HELO localhst544.com HELO emztd2134.com HELO 2mails2804.com
There are extra extra points for none of the homts being valid hostnames, despite the little .com stuck onto the end of the name, but that wasn't really necessary for scoring because that whole address range was already a winner in the *plonk* sweepstakes.