To be fair, it could have been an innocent mistake on the part of the person who signed up... maybe they meant to type .net instead of .com or something like that.
I contacted the vendor to tell them that the account is not authorized or known on my domain, and asked them to cancel, but they will not unless I send them an email using the 'from' address of the unauthorized account.
So, questions:
1) Is this a common thing? And if this is potentially illicit activity, what is this person thinking or hoping they'll be able to commit?
2) Even though I'd be using my own domain, should I intentionally impersonate someone who may (or may not) be attempting inappropriate activity in order to get the account removed? Wouldn't that - on its own - be a potentially dangerous or illegal act?
{sigh} modern problems.