Business Email

Email Spoofing: What It Is, How It Works, and How to Protect Yourself

Email spoofing is an attack technique where a sender forges the From address to impersonate someone else, and defending against it requires properly configuring SPF, DKIM, and DMARC on your domain.

Businesswoman using smartphone at desk with laptop and coffee cup.

Email spoofing is the act of forging a message's From address to trick the recipient into believing it came from a trusted source. It is the technical foundation of most phishing attacks targeting businesses.

This article explains how spoofing works, why the original email protocol allows it, and the specific configurations you must enable to protect your domain.

Why Email Allows Identity Impersonation

Email was designed in the 1970s on top of the SMTP protocol, built in an academic environment where trust was assumed. SMTP requires no sender authentication: any server can declare that a message comes from [email protected] even if it has no relationship with that domain.

The From: field displayed in your email client (Outlook, Gmail, Thunderbird) is simply free text. The protocol does not validate it by default. An attacker can set up any SMTP server and write whatever they want in that field.

This is not a bug — it is a consequence of how the system was designed decades ago. Modern authentication mechanisms (SPF, DKIM, DMARC) are extensions added later to compensate for that original gap.

How an Email Spoofing Attack Works Step by Step

Understanding the mechanism helps you appreciate why technical defenses are non-negotiable.

  1. The attacker picks a victim domain — your bank, your accountant, or even your own company domain.
  2. They set up their own SMTP server (or abuse a poorly configured bulk-sending service) and set the From: field to the address they want to impersonate.
  3. They craft the fraudulent message: a fake invoice, a request to change payment details, a fake urgent IT-support notice.
  4. The message reaches the recipient displaying the forged address. If the domain lacks correct SPF/DKIM/DMARC records, many mail servers accept it without question.
  5. The victim acts: downloads a malicious attachment, wires money to the attacker's account, or hands over their credentials.

Sophisticated attacks combine spoofing with visually similar domains (typosquatting): for example, @yourcompany-inc.com instead of @yourcompany.com. In those cases the spoofing domain actually exists, making detection even harder.

Types of Email Spoofing

Display Name Spoofing

The attacker keeps a real address but changes the visible display name. Your email client shows "CFO" while the actual address is [email protected]. It is the easiest to execute and fools users who do not check the full address.

Exact Domain Spoofing

The full domain is forged: From: [email protected] sent from external infrastructure. This is the most dangerous variant because the address looks perfectly legitimate. It is blocked by correctly configured SPF + DKIM + DMARC.

Cousin Domain / Look-alike

The attacker registers a similar domain (yourdomain-us.com, yourdom4in.com) and sends from it. SPF and DKIM do not block it because the impersonating domain has its own valid SPF. Defense here relies on user awareness and monitoring for similar domains.

BEC (Business Email Compromise)

Not always technically spoofing — sometimes the attacker compromises a real account. But spoofing is frequently the initial vector used to steal the credentials in the first place.

How to Protect Your Domain from Spoofing

The three fundamental technical measures are DNS records you configure in your domain or hosting control panel. If you have professional email on your own domain, a specialist business email provider can set these up for you in minutes.

SPF (Sender Policy Framework)

A TXT record in your DNS that lists which servers are authorized to send email from your domain. If a server is not on that list, the receiving server can reject or mark the message as spam.

Basic SPF record example:

v=spf1 include:yourprovider.com ~all

DKIM (DomainKeys Identified Mail)

Adds a cryptographic signature to every outbound message. The receiving server verifies that signature against a public key published in your DNS. If the signature does not match or is missing, the message can be rejected or flagged.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

Combines SPF and DKIM and instructs the receiving server what to do if a message fails both checks: none (report only), quarantine (send to spam), or reject (block at the door). It also generates daily reports so you can monitor your domain.

DMARC in reject mode makes exact domain spoofing virtually impossible.

Comparison: What Each Measure Blocks

Measure Display Name Spoofing Exact Domain Spoofing Cousin Domain
SPF No Partially No
DKIM No Partially No
DMARC (reject) No Yes No
User training Yes Partially Yes

Complementary Measures for Your Business

  • Enable two-factor authentication on all corporate email accounts. If credentials are leaked, the attacker cannot get in without the second factor.
  • Train your team to always check the full sender address, not just the display name.
  • Establish an out-of-band verification protocol for bank transfer requests or payment detail changes — a simple phone call is enough.
  • Monitor similar domains to your own with domain registration alert services.
  • Review DMARC reports monthly. They will show you if anyone is attempting to impersonate your domain.

Find more strategies for securing your business email in our business email resource center.

Key Takeaways

  • Email spoofing exploits a design weakness in SMTP: it does not authenticate the sender by default.
  • The three main types are display name spoofing, exact domain spoofing, and cousin domain attacks — each requiring different defenses.
  • SPF, DKIM, and DMARC together block exact domain spoofing, the most dangerous variant.
  • DMARC in reject mode is the minimum standard for any business using email on its own domain.
  • Team training is essential for the variants that technology alone cannot stop.

Not sure whether your domain has SPF, DKIM, and DMARC active? Contact us for a free audit of your email configuration — we will check everything and fix any gaps.

FAQ

Can I tell if someone is spoofing my domain right now?

Yes. Configure DMARC with an rua (aggregate reporting URI) pointing to your email address. You will receive daily reports from every server attempting to send email with your domain in the From field. Services like MXToolbox or DMARC Analyzer present these in a readable format.

Is SPF alone enough protection?

No. SPF only verifies the technical SMTP envelope address (Return-Path), not the From: field the user sees. Without DKIM and DMARC, an attacker can bypass SPF and still forge the visible address. All three records are needed together.

Does spoofing also affect Gmail or Outlook addresses?

Google, Microsoft, and Yahoo already enforce DMARC strictly on their own domains (@gmail.com, @outlook.com), making it very hard to spoof those addresses successfully. The greatest risk is custom business domains that do not have DMARC configured.

What is the difference between spoofing and phishing?

Spoofing is the technical mechanism — forging the sender identity. Phishing is the broader attack strategy — deceiving the recipient into taking a harmful action. Most phishing attacks use spoofing as part of their technique, but not all spoofing is phishing, and phishing can occur without spoofing (e.g., from a convincing cousin domain).

Further reading

Other providers and guides worth comparing:

← All