It's always a cat and mouse game, user+$RANDOM@example.org would still get through and you'd not be able to block that based on the sender (assuming you do it like most people, blacklist-based, rather than allocating new email addresses when you need them).
Of course, this only becomes an issue when the masses start doing it. I'm very surprised how few spammers remove tge +tag, given that that's semi-mainstream by now.
I do prefix+12RandomLetters@blahblah and every potential sender gets it's own random address. Then I use filters to move mail to predefined folders. What's left is spam.
If a mail comes in from an unknown sender to known address I know that the address is compromised.
Ideally I would like to plug my password manager to generate an address and automatically add email filters in place.
Although I was thinking about a service that would just give randomalphanumeric@example.com for all its users, so they would be on the same host and no connection between addresses could be implied. It could or even should be receive only.