Especially if the purpose for this is to catch spammers .... they'll find any domain that's open to sending trash from and sent if from there. They'll also spoof the return addresses (or even make them random).
The resultant effect is that some poor unsuspecting soul starts picking up bounces from mail s/he never sent in the first place, or your backtracking leads you to someone who never sent the mail in the first place

But a good place to start is to read the headers from the mail sent .... that should show IP addresses. If you can get the IP addresses and check them against a database such as
Domain Tools and check to see whether the sending domain is the same, then that might get you some of the way there.