I've been working on a paper regarding spam regulation...
I already knew that they could fake everything in the header, including the "from" address, just from personal experience. However what I didn't know was how helpless the community at large is to prevent this. It stems from the problems with SMTP, written in the early 80s, it was never meant for so much adaptation, and has no sender authentication.
The problem seems to be that we'll never get this 100-ton dinosaur to move/change protocols because everybody's already using this one.
Go with something that won't let you fake the headers, and it would be easy as pie to simply block the bastages and be done with it (because only then would you know that you've blocked the true source).