If you see traffic on that user, outgoing, it is going through your server. That is hacked, not spoofed. Not sure how it is doing it, I would start with delivery and obviously SMTP logs.
Remember kids, every time a spam message gets blocked, a nerd gets their glasses. spamhurts/July 15