This is what makes me thing it's auto-learning in this case:
Aug 26 14:58:33 maze sm-mta[4231]: i7QEwVOQ004231: Milter add: header: X-Spam-Status: No, hits=-104.9 required=5.0 tests=BAYES_00,\n\tUSER_IN_ALL_SPAM_TO autolearn=ham version=2.64
well, yes, but it doesn't need USER_IN_ALL_SPAM_TO to autolearn that message as ham, so that's hardly a suggestion that the all_spam_to is involved.
If you take away the BAYES and USER_IN_ALL_SPAM_TO, which it should, the score of the email is 0.
By default SA autolearns anything under 0.1. 0 is less than 0.1, learn as ham by default.
