or if in the headers they do..
"GET
http://www.url.com/shit.php HTTP/1.1" & vbcrlf
kill the connection .. that is another way to see if it is a proxy.. if they are going to it straight from ie or any other browser it will look like
"GET /shit.php HTTP/1.1" & vbcrlf
without your domain.. with the domain means it's coming from some type of proxy or another way of spoofing your ip