One thing I've noticed when this happens is that the spammer uses a randomly generated email address.... like
rob7392hd@yourdomain.net
so a good way to bounce those pesky undelivered notices is to switch off the catch all feature on your email admin. Then specify the email addresses you actually use like info@ sales@ and allow these to be delivered .... all the rest should bounce back.