I agree. In fact, I believe that the problem here rests less with the challenge / response system and more with the way the whitelist is managed.<SNIP> If someone sends an email they should accept a reply from the same person without this type of performance. Equally nobody should ever be asked to respond to a challenge the second or third time they send a message to the same person.