We were calling our case conversion function and our duplicate domain function in the wrong order. :o
That took forever to fix and find. I finally had to use a network sniffer to watch traffic and see exactly what data was coming in that enabled people to get around our ban lists.

