One idea would be to treat an email from someone you don't know with the normal level of suspicion for that case. The HTML would be converted to something safe for the user's browser. Image loading would be blocked. You would probably throw on a few spam points. Anything other than an introduction message gets lots of spam points. Anything that was properly signed would skip the spam process entirely.