It's been a while, but I can say that the commercial spamhaus DNSBL installation works based on the Github instruction. For example, I can see the hits based on the headers, like SH_ZRD_HEADERS_FRESH, SH_DBL_HEADERS, etc. You can send probes/test spam emails from Spamhaus, but it can't verify them even when the emails were blocked or quarantined properly. This is probably because PMG queues emails by default, therefore, it "accepts" all emails regardless if they are spam or not. We have been using the the paid/commericial DNSBL for about two months now and it's helping when it comes to the worst URLs and IPs out there. We use the DBL, ZRD, and HBL to scan the email content including the headers. I don't have any stats at the moment, I may do that next time, in the meantime I would like to know what you think.