If you read the Verisign documentation (which is quite excellent by the
way) on what they did and what they recommend you will see that they
thought about this.
I stopped reading the PDF when I saw the "Verisign Proprietary"
labels.
It is left as an exercise to the reader as to which is more efficient:
DNS NXDOMAIN or SMTP 550.
Semantically they're not equivalent, particularly for the targets of
an MX.
Would have been nice to get
some advance notice
"would have been nice" doesn't even get close.
IMHO it was irresponsible of them to do this without several months
advance notice to allow authors of automated systems which depended on
NXDOMAIN queries to notice this and without a stable documented way to
reconstitute the NXDOMAIN they're suppressing.
- Bill