* Generate two fingerprints (tools and sender), extract MUA name
* Record the MUA name as a search term, e.g. mua:thunderbird
* Add a User-Agent: header to our own outgoing messages
* The tool fingerprint depends only on the tool used to compose
* The new sender fingerprint includes details about the path the
message took through the network
This allows us to track sender reputation, so we can detect bulk
forgeries (phishing) and less sophisticated spear-phishing attempts.