Protected identity can run into two different problems:
- Some legitimate and acceptable sources will send messages that use the identity of an internal user. Mailing lists are one example, but hardly the only one. You need to know which apparent impersonations you will accept and which you will treat as threats. Then you need an exception mechanism to ensure correct disposition of both types.
- Some attackers will impersonate your users in the Friendly Name or the Subject text, without impersonating the user's actual email address. I assume that the protected identities feature will attempt to detect attacks of this type, but any such logic is expected to produce false positives when the protected name is common, like Mike Smith or Mary Jones (in the U.S.) or Li, Wei (in China). One way to minimize the risk of false positives will be to minimize the number of protected identities. Regardless of which identities you protect, you will need a way to create exceptions when false positives occur.
Exception planning is the most important part of any filtering design. Spamfoo is lacking in this area, but it is a new product with a lot of potential.