> >Eek! Bad guy forges 1 header and you don't scan it as you trust the
> >headers. Great idea, that one. Only a marketing guy could have
> >thought of that :-( Even Microsoft don't write code that is that broken...
>Augh.  I'm wounded to the quick. <g>
>It's really not all that bad because everybody's header line is different.
>The spammer isn't going to know 40,000 different headers and custom tailor
>his output to each.  A header that says "X-CBJ-MailScanner: Found to be
>clean" isn't going to get by a server that's looking for "X-ECS-MailScanner:
>Found to be clean" or vice versa.

Too right it will V. The spammers can easily discover your header setting.
Security by obscurity, never going to work.
