Here is a technote
http://www-01.ibm.com/support/docview.wss?uid=swg21212699
What triggers DCC to run?
Dynamic Client Configuration runs when the user authenticates with their home server, and either their Person document has been modified, or their assigned Desktop Policy has been modified since the last authentication. DCC is designed as a push mechanism only from the server to the client. The DCC updates settings on the user's workstation based on the current settings in the user's Person document and any Desktop Policies that are in place. For example, if changes are made to a user's Person document, DCC will detect the changes when the user connects to the server, and then push the appropriate changes down to the client.
DCC runs when the client is first launched or is restarted and the user opens a database on the home mail server specified in the location document.
My Suggestion is once you apply the policy if you do a drop all on the mail server the client will then authenticate to the mail server dynamic config will run and the user will be pushed the new / modified policy. I would suggest forcing a save to the user policy that the security policy is part of just to modify the last update date and time.