It would absolutely love it if the ironports devices would check for SPF on incoming mail. It would be great to be able to reject mail at the smtp conversation level if the spf record doesn't hard fails. My old mail servers were configured to do this, and we lost that ability when we implemented the ironports. This generated a lot of extra bounces.
DK would be nice but not so important to me. I much perfer rejecting during the smtp conversation.