I use ASSP spam filter. http://assp.sourceforge.netInstall it (use DMAY's contrib) and use the Spam Bomb feature to refuse HTML and return the error message of your choice.