I only have one path, but I am thinking of putting up a second relay in the path to see the outbound header...
This is what Spamassassin reports on this message.


It might be instructive to look at the original message that Tim McCord sent to Paul Imkamp rather than just the delivery report for it.  That way you could verify that the watermark went out on it.  Do you have multiple paths out or just the one?  Your message to gmail did look fine  
Rather than setting the action to high scoring spam, maybe try setting it to a value say 1.  The other spamassassin tests should push it over the top if its actually spam, and if its not, adding a little to the score shouldnt hurt too much.  Play with the score until you find a value that catches spam w/o incurring false positive.  Ultimately, you cant control what the far end does.
One thing though.  The mail coming in lacking a watermark shouldnt trigger the rule.  My understanding is, it fires when theres an invalid watermark AND no from user.  I have many messages that dont have anything in the from field (envelope from).  Thats a normal thing in an NDR and such but they come right through just fine.  I dont see anything in the post on pastebin to indicate that it failed because of the watermark.  Why do you think thats the case?
