Hmmm, you seem to be missing the point. Spammers monitor these spam lists in order to learn how to subvert spam filters, so why make there jobs any easier and your user any more vulnerable?
None of this stuff is a big secret, and besides, pretending to come from a domain like AOL or Amazon has resulted in spammers being sued successfully. Clearly they already know the tactics and have used them.
On the other hand, if I wanted to become a spammer, I assure you that I could get past your spam filters with near perfect success. Most of these guys don't even know how to fake a header properly and that would take someone moderately intelligent about 5 seconds to figure out. It's the fact that these guys are so dumb that makes it so that we can block them as effectively as we do. In the future, the only way around this will a distributed network of truly real-time, reliable blocklists where trusted people are promoting spam instead of spamtraps. Spamcop is doing this to some extent, but they lack in quality control because of the automation and lack of attention to whitelisting. They blocked PayPal the other day for at least several hours for instance...that got them demoted on my server. Same goes for MailPolice, who somehow tagged Ebay as porn.
Matt
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
--- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.
