There is an exploit that currently allows spamming users with llInstantMessage, it is not able to be blocked, and is relatively easy to perform. This is an issue I am seeing in increasing frequency, and since all existing tools are failing residents they're faced with the reality of accepting the unavoidable spam, or just disabling offline IM emails and logging out.
I am sharing the details of the exploit privately with Linden Lab, so I ask anyone reviewing this to please not discuss details or steps of the exploit in the comments or in public view to limit the spread of knowledge to utilize this exploit. It is already under active use by spammers, but not everyone knows about this and they don't need to until some sort of remedy is identified.
From the perspective of a viewer developer this is relatively trivial to solve for users of one specific viewer, but an issue of this nature and scale deserves a direct resolution at the source for all residents, perhaps a new way to block, or some new flavor of server side protections. Details up to LL to determine, now that the issue has been raised and awareness exists.