Recently I started receiving bounces from mail purporting to having been sent from addresses in my domain. But the addresses don't exist. So I thought that someone was faking the sender header and sending spam. I added SPF and domain-key records to try to combat this. However, either hotmail and yahoo don't check these or they ignore them because I'm still getting spammed.

Does anyone know of a way I can tighten fake sender policies & prevent this from occuring again?

