Hmm this is very simple to explain
Its called spoofing & is very achievable to do via Telnet:
http://en.wikipedia.org/wiki/Spoofing_attack
Anyone that is web technology fluent can achieve this. Sometimes it can last for a period of up to 2-3 weeks. Sometimes longer. The only real way to *try* and stop this is SPF Records & Domain Keys
http://en.wikipedia.org/wiki/Sender_Policy_Framework
&
http://en.wikipedia.org/wiki/Domain_Keys
Wether the VM email system supports this is another matter
Hope this helps