I see this, too. (Actually Google brought me here while searching for this issue.) The problem arises because SpamAssassin verifies the envelope-from (which has been rewritten) against the topmost "Received: from ..." header (which still indicates the host that delivered the original mail)...