You must ensure that the IPN indeed came from Amazon Payments. You can do this by verifying the value of the signature parameter contained in the response. For more information, see Verifying the ReturnURL and IPN Notifications.
signature