since it’s a hot topic. 😉
the absolute best way, that I have found, is to spend the money to purchase high end intrusion prevention systems.
the better quality ones are completely customisable, and do more than anti spam work, they also offer antivirus services.
since the goal is to have the fewest false positives these systems are more effective than simple content / subject filtering.
domain blocking is a guarantee of false positives.
the one I know the most about is Iron Mail.
this appliance uses a multiple scan, with filtering, and content heuristics, on top of the virus scan. it allows blocking of domains completely, as well as allowing all email through to specific addys in your network. administration is apparently 15 minutes a week. ( for a national isp in the us )
seems that this is the quality needed.
if the thousands that this type of solution isn’t available, work with filtering, blacklisting and whitelisting, with the expectation of false positives and about an hour a day in administration.