Could this be a case for stripping the: X-Confirm-Reading-To: Disposition-Notification-To: or Return-Receipt-To:, lines out of the message header? It seems like this is something a SPAM gateway could handle.
But more generally, MDNs and DSNs do serve a useful purpose when used conscientiously, and I don't think it makes sense to block them for all messages. The real problem isn't the notification requests themselves, but email clients that implement the notifications badly.