Correct, The assumption is that NAT was in use here.

After a quick phone conversation with Jared. We concluded that at least in
the specific case I was speaking about, I was correct in that nothing was
"Spoofed". However, Explained further in detail about what he sees from
other IP's on that list. And it clicked when he pointed out how many times and pop up as the src of the reply.

Forgive me for being slow, but doesn't this seem to imply that there isn't any antispoofing taking place at the GRE tunnel ingress?