If I'm sending mail on my ISP's SMTP server (which is the case for probably 99% of home users), the server will likely accept the message and queue it for delivery long before checking the validity of the To: address. Once that message rises to the top of the queue, the domain aaa.aaa will fail to resolve and the message will bounce, but the email trojan would never have any way of knowing that.
|