There should be a way to mark/flag accounts as suspicious / spammy, without outright deleting them.
I'm looking for a feature where I can automatically restrict an account that has performed shady activities like registering and not logging in for a month, sending masses of messages etc.pp. Deleting an account removes all the associated meta-data and makes recovery impossible in the case of erroneous flagging.
It would be great to be able to "tag" an account, and that tag would be automatically applied to all sessions of that account on login, restricting it. A specific implementation could restrict all flagged accounts to only contact a single support JID and reject any other form of communication.
A generic implementation could leverage mod_firewall to limit what the account's sessions are allowed to do, and provide different tags that can be applied.