There's a brand new overview of qmail at Security Focus today:
http://www.securityfocus.com/templates/forum_message.html?forum=2&head=5418&id=5418
I just scanned it briefly and it looks okay, but I already installed qmail so there's no way for me to check the accuracy of the individual steps.