May-12-10 13:16:41 82.249.21.94 <apoxidikyt3339@proxad.net> user unknown terry@somedomain.com;
The above line is a log from ASSP
A similar regex is mentioned in ASSP - Fail2ban, which is using log with a different pattern ( notice :[SMTP Error] 550 5.1.1 , this is not in the log above)
Replace the sample's <HOST> string with the IP address for your host value (or is this the remote IP...?). Otherwise, it's pretty straightforward and lean provided it works...I'm often limited to approaches like pseudocoder's attempt since my system isn't quite the best regex env.