Sadly, there’s no 100% guarantee you can avoid spam, with or without captchas.
Personally, I’ve resorted to either:
a) Flash forms with captchas (safe, even if you hack the SWF) - has obvious disadvantages for a tiny percentage of users without flash plugin installed.
b) HTML forms with random questions that only humans are supposed to answer. The question and answer pairs are only defined / stored in PHP (no cookies, no sessions, no JS, no hidden form fields).
e.g. "is fire hot or cold?" / "capital of France =" / "2 plus 5 ="
Obviously, these methods require addtl. work to setup and test, so I only really use it when the budget allows it.
whoever is sending it is somehow managing to send it to everyone (I am using a rather large mail selector dropdown). Any ideas how they are doing this, and how I could combat it?
Well, you have to validate / check EVERY user input. Not just the email-field (sender), but every single input field. PHP introduced a new set of tools for this with version 5: filters
http://uk.php.net/filter
It’s sad that even today you’ll find many forms where email-recipients are stored in hidden form fields, or all the checking is done client-side only (JS). That’s stupid and completely useless.