Actually, my claim differs somewhat. It is that most spam with free
provider MAIL_FROM values is not "forged" but that the spammer can
legitimately claim to own the MAIL_FROM value even if it has since
been terminated by the ISP. Your data is consistent with my claim as
Understood. One reason I chose a recent sample was to try and avoid
missing accounts due shutdown. Those tests were run within 24 hours
of the time I received the email. Of course, we have no way of
knowing when the spammer set up their software, or how long they've
been using that particular account.