Questions:
1) Is there user-by-user whitelisting as opposed to enterprise-wide? Blacklisting?
2) Can the administrator manage the enterprise-wide whitelist and user whitelists? Blacklists?
3) Is there a provision for excepting individual senders or whole domains from SPF testing while leaving it in place for other senders?
4) Is there a greylisting feature?
5) Is there AD lookup of valid recipient addresses? If so is filtering done at the SMTP level or later?
6) If there is a compliance requirement to not throw away ANY email (for example an email that has some invaled recipients along with valid ones or one sent to a misspelled address) can we send filtered emails to public folders or some other quarantine destination?
7) When exactly will EOP be available? Will it work in on-premise XS2K10 as well as on-premise XS2K13 environments?
8) What about database scanning? How can we scan for malware that might not have been detected on receipt?