Email Spoofing
Also known as: Sender spoofing, Domain spoofing, Forged From address, Exact-domain impersonation
Forging the sender identity of an email so a message appears to come from a trusted domain, defeated by publishing SPF and DKIM and enforcing DMARC.
How it works
Email spoofing is forging the sender identity of a message so it appears to come from someone the recipient trusts. The core weakness is historical: the protocol that moves mail never required the claimed sender to prove it owns the address shown to the reader.
Mail carries two sender identities. The envelope sender (Return-Path) is used by servers to route bounces, and the From header is what the person sees. They do not have to match, which is what makes a forged From possible without touching the victim's servers at all.
Three DNS-based controls close the gap. SPF lists which servers may send for a domain. DKIM adds a cryptographic signature that proves the message was authorised and unaltered. DMARC requires that at least one of them passes in alignment with the visible From domain, and tells receivers what to do when neither does.
Without an enforced DMARC policy, receivers have no instruction to reject a forgery, so exact-domain spoofing of your own brand reaches customers and staff with a trusted name on it. Attackers then fall back on lookalike domains, which are easier to detect and block.
Walk through it
- 1A message from your own CFO
- 2Read the authentication results
- 3Why was it delivered?
- Roll out DMARC without breaking mail
- Enforce on inbound and monitor
Staff forwarded a message that appears to come from the CFO's address at fabrikam-health.example, asking for an urgent gift-card purchase. The CFO says she never sent it. Open the full headers and read what the sending server claimed.
Full message headers
From: Dana Whitfield <cfo@fabrikam-health.example>
Return-Path: <bounce@mailer.bulk-sender.example>
Received: from mail.bulk-sender.example (203.0.113.77) by mx.fabrikam-health.example
Subject: Quick favour, are you at your desk?
Spot it
- DMARC fail for a message whose visible From is your own or a partner domain.
- From domain and Return-Path domain differ and neither aligns with the other.
- SPF passes only for an unrelated envelope domain, or SPF softfails or fails.
- DKIM absent, or the signing domain (d=) is not the From domain.
- Aggregate DMARC (rua) reports showing unknown source IPs sending as your domain.
- Internal-looking executive requests arriving from external IP ranges with no organisation banner.
Mail gateway
ts=2026-10-11T08:02:41Z from=cfo@fabrikam-health.example mailfrom=bounce@mailer.bulk-sender.example ip=203.0.113.77 spf=pass(mailfrom-domain) dkim=none dmarc=fail policy=none action=delivered
ts=2026-10-11T08:19:06Z event=user_report message_id=20311 reporter=finance.user@fabrikam-health.exampleDMARC aggregate report (rua)
source_ip=203.0.113.77 count=412 disposition=none spf=pass(unaligned) dkim=none header_from=fabrikam-health.examplekqlMicrosoft 365, DMARC failures spoofing your own domain
EmailEvents
| where SenderFromDomain == "fabrikam-health.example"
| where AuthenticationDetails has "dmarc=fail"
| project Timestamp, SenderFromAddress, SenderMailFromAddress, SenderIPv4, RecipientEmailAddress, DeliveryActionReplace the domain with your own. A burst here usually precedes a spoofing campaign.
splSplunk, From and envelope domain mismatch with DMARC fail
index=mail sourcetype=gateway dmarc=fail
| eval from_dom=lower(mvindex(split(from,"@"),1)), env_dom=lower(mvindex(split(mailfrom,"@"),1))
| where from_dom!=env_dom
| stats count by from_dom, env_dom, src_ipStop it
Enforce DMARC at p=reject
Publish SPF and DKIM for every legitimate sender, then move DMARC from none to quarantine to reject. Only an enforced policy tells receivers to refuse mail that forges your domain.
Authenticate every sender first
Inventory all services that send as your domain, including marketing, ticketing and HR platforms. Align each with SPF or DKIM before tightening the policy, using aggregate reports to find the stragglers.
Enforce on inbound as well
Honour DMARC policies on received mail, flag unauthenticated mail claiming internal identities, and give users a visible external banner and a one-click report button.
SPF, DKIM and DMARC DNS records (missing versus present)
Vulnerable
; DMARC monitor-only, no DKIM selector published
_dmarc.fabrikam-health.example. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@fabrikam-health.example"Hardened
fabrikam-health.example. TXT "v=spf1 include:_spf.mailprovider.example -all"
selector1._domainkey.fabrikam-health.example. TXT "v=DKIM1; k=rsa; p=<public-key>"
_dmarc.fabrikam-health.example. TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@fabrikam-health.example; adkim=s; aspf=s; pct=100"Move through p=none, then p=quarantine with a rising pct, before p=reject.
- End SPF with -all once every legitimate sender is listed, and stay under the ten DNS-lookup limit.
- Sign with DKIM using 2048-bit keys and rotate selectors on a schedule.
- Review DMARC aggregate reports weekly and onboard unknown senders or block them.
- Set a restrictive subdomain policy (sp=reject) and publish a null SPF for domains that never send mail.
- Enable inbound DMARC enforcement and alignment checks at the gateway.
- Consider BIMI after reaching p=reject so authenticated mail displays your verified logo.
- Require out-of-band confirmation for payment or credential requests, regardless of apparent sender.
If it already happened
Quarantine and purge delivered copies from all mailboxes, block the sending IP and any linked domains at the gateway, and warn the impersonated executive's likely targets.
Identify recipients who replied, paid or clicked, and treat them as compromised until cleared. Reset credentials and revoke sessions where a link was followed.
Move the domain to a stricter DMARC policy, publish any missing DKIM selectors, and recover or recall funds through the bank quickly if a payment was made.
Record the sender infrastructure, add detections for DMARC failures on your domain, and brief finance and executive assistants on verification procedures.
Check yourself
1. A message shows spf=pass but dmarc=fail for header.from=yourcompany.example. What best explains this?
2. Which DMARC policy instructs receiving servers to refuse mail that fails authentication and alignment?
3. Before moving a domain to p=reject, what is the most important preparatory step?