CREDENTIAL ABUSE RESPONSE 1. Disable or rotate the affected credential. 2. Preserve authentication and message logs. 3. Stop affected queue injection. 4. Identify unauthorized MAIL FROM and recipient patterns. 5. Remove queued abusive mail. 6. Restrict permitted senders and sources. 7. Monitor for recurrence.