I'm wondering if there's a chance to invoke external lists for inclusion in the policies. I'm thinking about known C2C domains / Spamhaus list e.g.

