Sack.dreamhost mail

I think this is a little different than some of the posts on this spam.

I got mail today from a sack.dreamhost address, which I usually just dump, but it was addressed to a specific alias I set up to receive notices from a only a particular airline. I’ve gotten spam on that address, so I know someone, somehow got ahold of that address. Since it’s a sack address that I got this time, does that mean that someone got it from the DH end or did some spammer go through the elaborate effort of matching up my DNS registration to the address before forging their headers?

Have you read this Kbase article?