spamassassin/postfix - not accepting the false "from" messages

Hello all,

I have typical spamassassin + postfix + clamav + amavis etc. etc..
configuration . Everything works well (autolearns etc..) and my users
nearly don't receive ANY spam except for spam that has their own
"reply-to" header. I have automatically whitelisted my relay_domains
in spamassassin and give them -100 points. Let's suppose that i am
using the xxx@xxx.com domain and all spam from !xxx.com is filtered
but spam with "reply-to" and "from" set to xxx@xxx.com is not filtered
(spamass automatically assigns -100 hits for such a message).

My question is - how to avoid this sittuation - users obviously are
very nervous saying "who was using my account ?" etc...

a) I think that disabling my domains whitelisting will cause some
non-delivery situations for messages from my domains to my domains
(clients using HTML , outlook, broken headers etc.)
b) Here's fragment from my postfix main.cf regarding configuration of
rejecting mails due to dns/etc errors.



