If mimedefang's spool directory only contains the files to be scanned, then the easier to maintain '/var/spool/MIMEDefang/** r,' is totally fine. If there is other stuff in there, may be it is worth using what I suggested above, but weighed against maintenance/fragility, maybe not.
I'm not up on current mimedefang, but doing something like this would be even better:
/var/ spool/MIMEDefan g/mdefang- */Work/ r, spool/MIMEDefan g/mdefang- */Work/ ** r,
/var/
If mimedefang's spool directory only contains the files to be scanned, then the easier to maintain '/var/spool/ MIMEDefang/ ** r,' is totally fine. If there is other stuff in there, may be it is worth using what I suggested above, but weighed against maintenance/ fragility, maybe not.