1) maybe you could set up a filter to catch any email with subject containing [junk] and direct it back to inbox. would have to be done per user
2) I whitelist by editing /opt/zimbra/conf/salocal.cf.in adding lines like whitelist_from *@zimbra.com or whitelist_from
user@example.com
You can also blacklist_from
user@example.com in this file
then as zimbra user restart zmamavisctl