What does this victim notice? ZERO! Unless he starts out sending mails with http://123.123.123.123 (his IP) and this is not very likely is it? I dont see anything liked yet that would surprise me, you?
Good point yes, as long as the RBL lookup implementation only checks for URI's as you state.
Regards, KAM