Short answer is yes the IP is real but Domain name can be forged.

Show us the headers of that virus/email and you will get a definite answer.