It would be helpful to see the relevant headers to understand how it was spoofed, and if it would have been obvious from looking at the headers.