I noticed replies tend to have the following Header information:
So this might be a rule I can trigger on.
You can create a dictionary to look for the desired terms and have it add a negative number to the spam score. However, that does add a potential vector for spammers to try and slip more mail past the filter. There isn't a built in way for MEG to know this is a real reply as opposed to someone faking it.
I tried to create a dictionary with a negative value and the field provided for inserting a value doesn't appear to allow me to insert a - sign. I tried single digit, I tried copy and paste from notepad. It won't take it. It doesn't matter, I'll play around with it. I think rather than a value, I'll just put it in as an allowance rule. I do understand it creates a potential hole for spam that illegitimately shape the header, but I've done a fair analysis and have yet to see one hit our filter with this type of string in the header that isn't legitimate.