ISPConfig does not add any load protection configuration or advanced iptables filtering. The firewall just opens / closes ports with iptables and the IMAP daemon is not configuret at all by ISPConfig.
But I thought the spamfiltering and antivirus checking takes place as the mail enters the server?
What did you do exactly which causes too much time? You posted above that you got 1200 spam mails. If a mail is received on your server, it is scanned trough postfix and procmail.
Aditionally, which imap daemon do you use. Did you use the exact same daemon software and version for your other test?