Not sure if this will ever happen, but on the subject of spam...
I'm sure the xf security token could be embedded in the mail headers of the notification email.... this header *should* get sent along with the reply and thus can be validated and eliminate spam.