What to exclude from scanning: the profile folder, or the Inbox file plus other mailbox files?
One quick comment about the 2nd [now the 3rd] of the “basics of e-mail security”: excluding TB’s profile folder from scanning is NOT “the exact equivalent” of excluding OE’s .dbx files. One is a directory, and one is a file type that can be specified by its extension. The closest equivalent would be excluding TB’s Inbox, Junk, Sent, Drafts, and all other mailbox files, individually by name (since they cannot all be excluded by file extension). The Symantec link advocates excluding the Inbox, not any whole directory containing the Inbox. The distinction is not insignificant, since malware could land in the profile folder if, say, a user were for some reason to save an attachment there. It’s unlikely, but possible. For this reason, I can’t see that excluding the whole profile folder is sound security advice.