FYI,
This is not the fault of drupal, but I got a customer that said that they were hacked because the TO and CC for request password did not have their email address for the site they put in under site configuration...
I went the long way around the barn till testing many things then went back to the basics and realized
that drupal was okay, the email address was not...
They had something like support@mydomain.com.com
notice the com.com on the end... welll someone registered com.com and aliased the rest....
TRY THIS
nslookup whatever.com.com
and you get c18-ss-1-lb.cnet.com
So if your user accidently put in email support@mycompany.com.com
it really becomes support@c18-ss-1-lb.cnet.com
Go figure... hopefully cnet.com is aware of this and is not taking advantage of harvesting emails for other users that do this particular mistake...