"v=spf1 ip4:216.32.180.228 include:spfa.microsoftonline.com include:spf-exacttarget.microsoftonline.com include:spf-msods.microsoftonline.com include:spf-mfa.microsoftonline.com include:_spf-ssg-a.microsoft.com -all"
They've got the "-all" in there, which is good, but also a whole bunch of "include" directives, including one that refers to ExactTarget a third party MSP, but the one that appears like it could possibly be the problem is the last one. That contains a further include, and in there is "spf.protection.outlook.com". All the includes do have "-all" but, AFAIK, that domain covers the outbound mail gateways for a least some parts of the Outlook.com webmail service, so if the spammers have been able to a suitable account using a server within one of the many IP ranges listed in that include that doesn't properly restrict the domains able to send their mail, then they are good to go.
The more cordial the buyer's secretary, the greater the odds that the competition already has the order.