Spam defense tip for folks self-hosting email: the #1 performing rule I have (accounts for ~75% of blocked messages) is rejecting forged EHLO hostname.
That is, client greeting us with EHLO followed by a hostname that does not resolve to the IP address they're sending from.
It's dead simple but super effective. Does need a few allowlist exceptions for known broken senders, most notably Microsoft.