I wouldn't be able to write you a rule, I'm not terribly familiar with RegEx.
I can make some suggestions though to try lowering your suspected spam threshold and make sure that when you look in the message audit log that the sender is not being whitelisted.
Could you take a screen shot of one of the messages from the message audit log and post it?