Forgive my ignorance here - but how did the fake email manage to have been signed by facebook.com? If anyone knows, I'd love a detailed explanation or a reference link. Thanks!
<?php mail('exampleperson@example.com', 'Example Subject', 'Example Message', 'From: admin@facebook.com' ); ?>