I tested the one below and it worked for my system.
By the way, I added the hypen (-) in place of the spaces because the system only allows for _ (underscores) or - (hypens, dashes).
Also, for this entry:
mail-from == "*out\\.company\\.internal$"
Instead of *.out.company.internal, I had it look to see if the mail-from ended with that domain using the "$" regular expression, which means "ends with". The Advanced User guide provides detail on this.
If you look at the Advanced User guide, the Policy Enforcement -> Filters section, there is a wealth of information and examples on message filters. The Advanced User Guide PDF can be downloaded from the Support Portal in the Email section.
Also, if you need to test this, I would suggest using the Trace tool from the GUI interface(System Administration > Trace).
Then you can do a test run to see how the message filters would match and what would happen to the email if it actually went through the system.
Head-Office-Spam:
if (recv-listener == "IncomingMail") AND (mail-from == "out\\.company\\.internal$")
{
if (reputation < -2.6 )
{
quarantine("HUB-Tagged-Spam");
}
else
{
deliver();
}
}