Challenge-response has a major flaw...how do two people, both using challenge-response ever make contact with each other?
1. Person A sends Email to Person B...
2. Person B email service sends a challenge response email to Person A...
3. Person A email service responds back with a challenge-response email to Person B...
4. Repeat...
One possible solution is have Person A's email system keep track of recently sent email addresses and allow challenge-responses through from those email addresses. Seems like the solution...well, except until spammers send out spam that appears to be valid challenge-responses...eventually folks don't know a legitimate challenge response email from a forged one.
Email is becoming more useless by the day...perhaps SPF
http://spf.pobox.com/ and the proposed subscriber supported (~2K per year) .mail TLD will truly curtail spam.
Ron