How about adding some filter rules for the spam account (what ever your system called it), that deletes any emails from untrusted users. These could even be put in the spam user address book, and the rule set to check them against the address book.
Or even do the reverse, and reject all but users in the address book.
-Si-