>It does make sense.  The spammer does fake a "To" address, say 
>"null at bitbucket.kr". It's a known bad address. He or she then places the 
>desired recipient in the "from" address, so that it bounces back to the 
>"from" address. Or at least that's how I interpret what was happening on 
>our machine. We've got all relays closed down hard. We had to call our 
>upstream, who then shut these 4 networks off.

Hi Frank

Since spammers start taking desperate approaches like this, it seems
to get harder and harder for them to earn money   :)

Some day, the whole spook is gone...

Mike

