What I’m seeing seems to be different than they typical zombie/drone/compromised server.
I looked up a bunch of the most recent spam and their domains were all very recently registered at enom.com - it’s not like they are using fictional/spoofed domains, or utilizing a compromised mail server on an existing domain.
Today I received three emails in a row - identical subject, identical body - from three different domains (and different IPs, and different mail accounts) - however a whois search showed all three domains were all registered at enom on the same day, within 15 minutes of each other!
All anonymously registered of course!
[SIZE=13px][FONT=arial]From:[/FONT][/SIZE][SIZE=13px][FONT=arial] [/FONT][/SIZE][SIZE=13px][FONT=arial]Bridget Matos <[/FONT][/SIZE][SIZE=13px][FONT=arial][email protected][/FONT][/SIZE][SIZE=13px][FONT=arial]> [/FONT][/SIZE]
[SIZE=13px][FONT=arial]Message-ID:[/FONT][/SIZE][SIZE=13px][FONT=arial] [/FONT][/SIZE][SIZE=13px][FONT=arial]<.[/FONT][/SIZE][SIZE=13px][FONT=arial][email protected][/FONT][/SIZE][SIZE=13px][FONT=arial]>[/FONT][/SIZE]
[SIZE=13px][FONT=arial]From: March 7th Alert <[email protected]> [/FONT][/SIZE]
[SIZE=13px][FONT=arial]Message-ID:[/FONT][/SIZE][SIZE=13px][FONT=arial] [/FONT][/SIZE][SIZE=13px][FONT=arial]<[/FONT][/SIZE][SIZE=13px][FONT=arial][email protected][/FONT][/SIZE][SIZE=13px][FONT=arial]>[/FONT][/SIZE]
[SIZE=13px][FONT=arial]From: ayden Wilkerson <[email protected]> [/FONT][/SIZE]
[SIZE=13px][FONT=arial]Message-ID:[/FONT][/SIZE][SIZE=13px][FONT=arial] [/FONT][/SIZE][SIZE=13px][FONT=arial]<[/FONT][/SIZE][SIZE=13px][FONT=arial][email protected][/FONT][/SIZE][SIZE=13px][FONT=arial]>[/FONT][/SIZE]
So - three different domains, three different IPs, but the exact same email! ( [SIZE=13px][FONT=arial]Subject: [/FONT][/SIZE][SIZE=13px][FONT=arial](March 7th) Your personal credit rating lowered (see why) )[/FONT][/SIZE]
The links embedded in these emails DO work ( qualify.html?date-check=781065633050+69771368seen-your- ) and they redirect to live sites (Checkmate background checking service…)
Is enom just turning a blind eye to this type of obvious spam activity? I’m pretty sure the three domains above were all registered on the same day, within minutes…not a hacked website, but an obvious attempt to send spam.
I sent [email protected] the info…I’m sure they’ll get right on it! 
Too bad you can’t filter based on the registrar of the domain instead of the host.