Blacklisting a domain based on From: or Reply-To: fields in spam messages (or even HELLO response string - IP is probably OK, but that's just the last hop) is utterly moronic. Everybody's grandmother can spoof those.
I am afraid we will have to switch to some kind of authentication rather soon, with all unwanted consequences for privacy; otherwise, e-mail will become useless...

One good idea I saw a few months ago is to only have originating SMTP server authenticate itself (its domain--sign it together with timestamp and message ID and hash or something like that); user could still be anonymous (for the rest of the world, anyway). It would then be the originating server's responsibility not to send spam.