Is up to your environment. If your PMG is same network with your email server, configure firewall to redirect SMTP to your PMG instead of the email server.
If the default mail filter rule and SA score do not work for you. You have to create custom mail filter rule based on your situation and requirement.
https://pmg.proxmox.com/pmg-docs/pmg-admin-guide.html#chapter_mailfilter
Another option is custom spamassassin configuration...
Maybe the exchange had been compromised or some compromised client sending spam through the exchange.
Will the usage back to normal if you block or disable exchange outgoing connection to PMG?
Create a highest priority rule with who object domain list.
To bypass SPF checking, add the domain list to Mail Proxy -> Whitelist.
But I am not sure will above setting bypass reject unknown sender/clients as I did not enable it.