Stop being so strict with spoofing
I'm very disappointed in what appears to be recent security changes that don't allow emails that came from a spoofed source but are actually from legitimate website forms.
We run a website with a form that encourages thousands of customers to go on trips. One of the form fields is TRAVELER 1 EMAIL. The form is scripted to send a duplicate of the submitted form (sort of like an autoresponder), using the [traveler-1-email] tag. This worked for years, but now it doesn't and has put us in a big bind with no warning.
Meanwhile, I DID receive 50 spam advertisements in my inbox, several of which I have previously flagged as spam. THOSE got through, but not legitimate business emails. Bottom line is that you have over-engineered the security features to a point where email is becoming useless.