You should definitely upgrade to the latest version, 7.4.
I also have a few more questions:
1. Is SMTP authentication enabled for users, or can anyone access the service?
2. Is the server operating in Server Only mode?
However, all that said I agree with your hypothesis that...
... [their] domain name was being used as a return address by some spammer so I am wondering if this is a consequence of that predicament.
I would upgrade to 7.4, and update fetchmail to the latest version (in the smecontribs repository), as a first step. 7.1 is very old now.