Perhaps I am not understanding your question properly. This script you are using to process the HTML forms and send the mail, did you write it yourself? Is the spam being sent to your clients only, or are the spammers relaying mail to otheer people via your script? Have you looked at things like