It was accidentally noticed that the variable $fU gets the user part of userinfo SIP URI (although it is logical and described in the document RFC2543).
I got message below and my spam filter based on $fU passed it inside the network, as $fU was test