I found this very interesting. I was wondering about what your team thinks about two possible features that I did not see covered, which IMHO would help to further minimize false negatives, false positives, and administration load:
- Custom Message Weight: will it also support a simple list of "Bad Attachment Types"? E.g. any message with .exe, .scr, etc. could be deleted, archived or otherwise processed within the Exchange Server environment.
- Turing test mailback and response processing: I think this is vital, I mean, to give real and honest users a chance, rather than making them collateral victims of the sum of all the technology we increasingly use against spam. And for doing all of this without requiring the admin to take action.
Also, what about integration with client-side whitelists? E.g., can the end user force-enable some senders in Outlook 2003 (Safe Senders, Safe Recipients), and make sure these get through even if Exchange Server might otherwise mark them as UCE? Again, the idea is to empower the user and make the system more responsive to urgent needs, and at the same time reduce the load on the admin.
Thanks for listening.