This is why I said above:

"I won't add isps to trusted hosts, since they are actually indirectly the source of most spam with their users on dsl networks with compromised machines."

If you use an ISP for forwarding then, you're unfortunately out of luck at the moment with this. However you are right, you can narrow down the problem by making trust a tuple of "host/rcpt-to-address" that's trusted rather than just "host". When I add "per user trusted hosts", i'll keep it in mind...

