This is really a per environment question. Your actions you stated above are valid. Creating rules that exclude content based off common triggers isn't a bad practice.
There are other ways to excluse if you are using say a common file by creating a signature from the file (a common document sent to customers that has trigger words).
A more practical question would be if before you placed the exclusions in place were the valid incidents you were generating in the 200-400 range? I realize you generated more false positives before but for the actual incidents were they in this range? If so, I would say you don't have anything to worry about.