Phorm (http://www.phorm.com) is probably the most secure formmail script I have ever seen - if there is a way to spoof it, I can't figure it out. You DO NOT have to put the recipients email in a hidden field in the script - every form can have it's own config file outside of a web accessible directory. It can send auto-replies and log info into (and retrieve autoresponder data out of) a mysql database and has excellent documentation. There is a web-based installation and configuration utility available along with several plugins.
Phorm is free but I gave the dude $15 for the plugins and config module. Well worth it.
(wow, I re-read this and it looks like a commercial - but I have nothing to do with the script or it's author.)