You could take a look at the senderbase reputation score (https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117919-technote-cdc-00.html) And make an Content filter for certain range of score, so you could add and disclaimer...