Possible solution: Allow HTML mails only from contacts in the address book. Loading external data (graphics / web bugs), executing JavaScript, etc. should stay diabled by default.