On this page
Definition
Email spoofing is the practice of sending an email that appears to come from a trusted person, business or domain when it was actually sent by someone else. Attackers use it to impersonate brands, trick staff, request payments, spread malware or make phishing messages look more credible.
Email spoofing cannot be eliminated entirely, but correct domain authentication, careful DNS configuration, staff awareness and ongoing monitoring can reduce the risk.
Key Takeaways
- Email spoofing makes a message appear as if it was sent from your domain, even when it was not.
- SPF, DKIM and DMARC help receiving mail servers check whether a message is authorised and trustworthy.
- Authentication improves email deliverability and trust, but it does not guarantee inbox placement or stop every phishing attempt.
Quick Explanation
How Email Spoofing Works in Plain English
Email Authentication Reduces Risk, It Does Not Remove It
Business Impact
Why Email Spoofing Is a Real Business Risk
How It Works
What Happens When a Spoofed Email Is Sent
The technical details can become complex, but the basic flow is easier to understand when broken into stages.
-
An attacker prepares a message
The attacker creates an email that uses a trusted name, address or domain in the visible sender details. The message may copy your branding, tone or invoice format to appear believable.
-
The receiving mail server checks the domain
The recipient’s mail system looks at technical signals such as SPF, DKIM and DMARC. These checks help determine whether the message is authorised to use the sending domain.
-
The message is accepted, rejected or filtered
Depending on the domain’s authentication records, the sender’s reputation, the message content and the recipient’s mail rules, the email may reach the inbox, be sent to spam, be quarantined or be rejected.
Key Email Authentication Terms
These records are published in DNS. They help mail servers assess whether email using your domain is legitimate.
- SPF
- Sender Policy Framework tells receiving mail servers which systems are authorised to send email for your domain. If a server is not listed, the message may fail SPF checks.
- DKIM
- DomainKeys Identified Mail adds a digital signature to outgoing email. The receiving server can check that signature against a DNS record to help confirm the message has not been altered.
- DMARC
- Domain-based Message Authentication, Reporting and Conformance connects SPF and DKIM to a domain policy. It tells receiving servers how to treat messages that fail authentication checks.
Spoofing, Phishing and Compromised Accounts Are Not the Same
These problems are often discussed together, but they require different responses. Understanding the difference helps avoid wasted time during an incident.
| Issue | What It Means | Typical Response |
|---|---|---|
| Email spoofing | A message pretends to come from your domain or identity, even though it was sent elsewhere. | Review SPF, DKIM and DMARC records, check DNS alignment and monitor unauthorised use of the domain. |
| Phishing | A message attempts to trick someone into sharing information, clicking a link or making a payment. | Train staff, report suspicious messages, review filtering rules and avoid entering credentials through email links. |
| Compromised mailbox | An attacker gains access to a real mailbox and sends messages from the genuine account. | Reset credentials, revoke active sessions, review mailbox rules, enable stronger security controls and investigate activity logs. |
Risk Reduction
How Businesses Can Reduce Email Spoofing Risk
Email Spoofing Risk Review Checklist
Use this checklist when reviewing whether your domain is properly protected against common impersonation risks.
-
Check SPF, DKIM and DMARC records
Confirm the records exist, are correctly formatted and match your current email provider, website forms and approved third-party sending tools.
-
Review who controls your domain and DNS
Make sure domain ownership is clear, registrar access is secure and DNS changes are not being made by unknown or unmanaged providers.
-
Test business-critical email flows
Test normal mailbox sending, website form notifications, invoice emails, booking confirmations and any automated systems that send from your domain.
Common Email Spoofing Protection Mistakes
Most issues we see are not caused by one missing setting. They are usually caused by old providers, unclear DNS ownership, rushed migrations or unmanaged sending tools.
Adding every sender to SPF without review
Do this instead
Only include platforms that still send legitimate email for the domain. Old services should be removed where they are no longer used, otherwise the record becomes harder to maintain.
Turning on a strict DMARC policy too quickly
Do this instead
Review legitimate sending sources first. A strict policy can be useful, but applying it before testing may cause genuine business email to fail.
Assuming Microsoft 365 setup alone solves everything
Do this instead
Microsoft 365 can provide a strong email platform, but DNS authentication, third-party senders, domain access and website form delivery still need to be configured correctly.
Signs Your Domain May Need an Email Deliverability Review
These symptoms do not always prove spoofing is occurring, but they are worth investigating because they can point to weak authentication or DNS issues.
Customers receive suspicious emails that appear to come from your business
Likely cause
Your domain may be easy to impersonate, or attackers may be using a similar-looking domain.
Solution
Review SPF, DKIM and DMARC, check domain lookalikes where relevant and advise customers not to rely only on the visible sender name.
Your legitimate emails are going to spam
Likely cause
Authentication may be missing, misaligned or incomplete, or your sender reputation may be affected by past sending behaviour.
Solution
Audit DNS records, test mail flows and review the platforms sending on behalf of your domain.
Website form emails are not arriving reliably
Likely cause
The website may be sending mail in a way that does not align with your domain authentication or mail provider requirements.
Solution
Configure authenticated sending where suitable and test form delivery across the main business inboxes.
Benefits and Limits of Email Authentication
What It Helps With
- Helps receiving mail servers identify messages that are authorised to use your domain.
- Improves trust signals for legitimate business email when records are configured correctly.
- Provides a clearer technical foundation for diagnosing email delivery and domain impersonation issues.
What It Cannot Guarantee
- Does not guarantee that every legitimate email will reach the inbox.
- Does not stop attackers from registering similar-looking domains.
- Does not protect a mailbox if the real account credentials have been compromised.
Professional Support
When Should a Business Get Help?
Our Approach
How We Approach Email Spoofing and Domain Authentication
Email Spoofing FAQs
These short answers cover common questions businesses ask when reviewing email spoofing risk and domain authentication.
Can SPF, DKIM and DMARC stop all spoofed emails?
Is spoofing the same as someone hacking my email account?
Should every business have a DMARC record?
Need Help Reviewing Your Email Setup?
If your emails are going to spam, clients have reported suspicious messages, or you are unsure whether your SPF, DKIM and DMARC records are correct, we can review your domain and email configuration and explain the practical next steps.