I did think of redirecting all the spam right back to the sender, but that wouldn't work because they usually don't use valid From: addresses -- and worse, they steal somebody else's From: address. Plus, it wouldn't trick the spammer into thinking they sent their spam successfully.
Anyway, I'm not really versed in this sort of thing so there might be something I'm not seeing, or there might be an even better way to get back at FormMail.pl hijackers that I'm not seeing -- which is why I'm posting, to see what the experts have to say.
Redirect all requests for FormMail to a Trap.pl script, which adds their URL to a banned environment in your htacccess.
I found the script for Trap.pl here [webmasterworld.com] at WW.