bounce is better. That way as an admin you don't get into a situation you aren't comfortable with. Lets face it, that's between them and their SO's unless it impacts the business, and then its up to their managers and HR to request logs. Whatever my personal feelings are on it, my business one pretty much ends up correcting it and letting it go since that is/was the policy. Of course, I'd then immediately change the policy next week to bounce typoed internal emails after that. I generally follow a don't ask, don't care policy regarding people's personal crap at work...

I've accidentally ended up in similar situations myself on occasion due to monitoring the internet firewall for things like blocked legit sites that needed unblocked and run into someone surfing NSFW's. I'd typically just take them aside, QUIETLY, let them know they could get in trouble if another admin or the security guys saw that, and then let it drop. I generally wouldn't see their userid again pop up again, except for one of the night security guys... yeah, you don't wanna know...

