I have the same Problem.
The SPF could not work unless you set a spf like "v=spf1 ip4:xxx.xxx.xxx.xxx -all" for each domain . And then you have to set the filter SPF to deny when spf fail.
You can create specific rules for sa.
body RP10 /googleapps-espana.com/i
score RP10 20.0
describe RP10...