Parameters of DNS transactions associated with DNS MX record queries,
which may be performed by mass-mailing worms from a host computer system,
are detected at a DNS proxy and collected. An outbound SMTP transaction,
such as an e-mail message, received at an SMTP proxy is stalled at the
SMTP proxy and a determination is made whether malicious code activity is
detected on the host computer system by correlating the parameters
associated with the DNS MX record queries and the e-mail message. In one
embodiment, above a specified threshold rate of DNS MX record queries to
resolve SMTP server IP addresses, followed by the use of a resolved SMTP
server IP address to send the e-mail message, an assumption is made that
the e-mail message is generated by a worm, such as a mass-mailing worm,
and protective action is taken thus preventing propagation of the worm,
or other malicious code, via the outbound e-mail message.