If you have one MX and you create a fake low MX and a fake high MX (or
many fake high MX) about 75% to 95% of your spam goes away. It's that
simple.
How do you deal with the false-positives, legit servers that are blocked
by this configuration?
There aren't any false positives. That's what is so great about this
trick.
How can you prove it?
I keep a copy of every single message I greylist or blackhole. It makes
it trivial to prove I didn't drop a really important message.
If I don't even know that connection attempts are failing, how can I
claim I haven't lost anything?
As other people have mentioned, there are MXs which don't retry properly.