Randy Brukardt of rrsoftware.com mentioned that checking plain domains occurring in message bodies against SURBLs was pretty productive. (E.g., look for domain.com in addition to www.domain.com or http://www.domain.com).
Perhaps this could be something interesting to at least try experimentally or to think about.
Jeff C.