Hmmm... I like the idea, but won't spammers simply start using real addresses that just point to /dev/null instead of a legit account? This would add them to your whitelist. I rather like SpamAssassin's heuristics (sp?). We still get a few spam messages, but my users know to forward them to me and I just add them to my blacklist, never to be heard from again. In 178,000 emails filtered by SpamAssassin, only 2 have been tagged as spam when they weren't, and these were horribly written emails, with things like broken html in the message body, everything in all caps, and weird fonts.