It's been 3 years or so since I've been in the business of killing spam, but I recall never EVER caring about the domain name that is so easily forged anyhow. I only ever cared about IP addresses. I even wrote some nifty stuff to analyze my SA logs that once an IP had sent me a configurable amount of spam over a configurable score, that I added the IP to my blocklist and wouldn't allow it to even connect to my server. If I saw enough junk from the same subnet, the whole subnet would eventually be blocked. There was also a timeout on these entries, but they became progressively longer the each time they were re-added to the list.