Email spoofing: how scammers send email in your name
Short answer: Email spoofing means sending an email with a forged sender address so that it looks as if it came from your company. Scammers can use your exact domain unless it publishes a DMARC policy of quarantine or reject; together with SPF and DKIM, that policy lets receiving mail systems recognise and stop the forgeries. It does not stop look-alike domains or a real mailbox that has been taken over, so employees still need to recognise suspicious emails.
The sender address on an email is as easy to fake as the return address on an envelope. The protocol that carries email (SMTP) was designed decades ago without any check of who the sender really is. Unless the owner of a domain publishes rules saying which servers may send in its name, a receiving mail system cannot tell a genuine email from a forgery.
Those rules are three DNS records: SPF, DKIM and DMARC. Below is what each one does, how to check your domain and how to turn protection on without blocking your own email.
Four ways scammers use your name
- Your exact domain
- The From field shows accounts@yourcompany.com, exactly your address. This is the form that SPF, DKIM and DMARC can stop, but only if DMARC is set to quarantine or reject.
- Only your name
- The display name says “Anna Kowalska, CEO”, but the address behind it is a free mailbox. DMARC does not help here, because the domain is not yours. The person has to check the address.
- A look-alike domain
- yourcompany-invoices.com, or rn instead of m. The scammer registers the domain and can give it perfectly valid SPF, DKIM and DMARC records. Only a person who looks closely spots it.
- A real mailbox that was taken over
- The email really does come from your supplier’s or colleague’s account, because someone stole the password. It passes every technical check. Here the defence is two-factor authentication and confirming payments by phone.
Why it matters to your company
- Customers and suppliers receive fake invoices and “new bank details” from your address, and the loss often lands on your relationship with them.
- Your employees receive “internal” emails from your own domain, which they trust more than any outside email.
- Delivery of your genuine email suffers. Since 1 February 2024, Gmail requires everyone who sends to Gmail accounts to use SPF or DKIM, and senders of more than 5,000 messages a day to use SPF, DKIM and DMARC.
How SPF, DKIM and DMARC work together
- SPF (Sender Policy Framework)
- A DNS record listing the servers allowed to send email for your domain, for example v=spf1 include:_spf.google.com ~all. The receiver checks whether the email came from one of them. One domain has one SPF record, and it may trigger at most 10 further DNS lookups.
- DKIM (DomainKeys Identified Mail)
- A digital signature your mail system adds to every email. The receiver checks it against a public key published in your DNS and so knows the email came from your system and was not changed on the way.
- DMARC
- Your instruction to receivers: what to do with an email that uses your domain in the From field but fails the checks. p=none only monitors, p=quarantine sends it to spam, p=reject refuses it. DMARC also sends you reports about who sends in your name.
The key detail is alignment. An email passes DMARC when SPF or DKIM passes and the domain it checked matches the domain the recipient sees in the From field. That is what stops a scammer who sends from their own server but writes your address in the From field.
How to check your domain
Enter your domain in the free SPF, DKIM and DMARC checker. It reads the public DNS records and shows in plain words whether scammers can send email in your name, what is missing and which records to add. Nothing is changed on your domain, and the domains you enter are not stored.
You can also look at a single email: in Gmail choose “Show original”, in Outlook open the message headers. The Authentication-Results line shows spf=, dkim= and dmarc= with pass or fail.
How to turn on DMARC without blocking your own email
- List every service that sends email in your name: the mail system, the newsletter tool, invoicing and accounting software, the CRM, the website’s contact forms.
- Add them all to one SPF record and keep it within the 10-lookup limit.
- Turn on DKIM signing in each service; each one gives you the record to add to DNS.
- Publish DMARC with p=none and an address for reports. Watch the reports for a few weeks to find senders you missed.
- When every genuine sender passes, change the policy to p=quarantine, and later to p=reject.
A domain that sends no email at all can be locked straight away: v=spf1 -all in SPF and p=reject in DMARC. Do this only if you are sure nothing sends from it, not even automated notifications.
What DMARC does not stop
DMARC protects your domain; it does not protect your inbox from other domains. A look-alike domain, a sender who uses only your name, a supplier whose domain has no DMARC, or a supplier whose mailbox was hijacked will all reach your employees. That is why companies combine domain protection with training: employees who have practised on realistic emails notice the wrong domain, the unusual request and the pressure to hurry. How to spot these emails is covered in How to spot a phishing email and CEO fraud and invoice fraud.
Opsinel sends employees realistic phishing simulations, including emails from look-alike domains, and shows a short lesson to anyone who clicks. More on how phishing simulations work.
Try it yourself
Can scammers send email in your name?
A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.
Could you spot a phishing email?
10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.
Take the phishing quizFrequently asked questions
What is the difference between SPF, DKIM and DMARC?
SPF says which servers may send email for your domain. DKIM adds a signature proving the email came from your system unchanged. DMARC ties the two to the address the recipient sees and tells receivers what to do when the checks fail.
Can DMARC block my own emails?
Yes, if a service that sends in your name is missing from SPF and has no DKIM. That is why you start with p=none, read the reports and only then move to quarantine and reject.
Is p=none enough?
No. p=none only collects reports; forged emails are still delivered. It is the first step, not the goal.
How long do DNS changes take?
Usually from a few minutes to a few hours, depending on the record’s TTL. The whole rollout, from p=none to p=reject, usually takes a few weeks while you check the reports.
How can I tell whether an email I received was spoofed?
Open the email’s headers (in Gmail “Show original”) and find the Authentication-Results line. dmarc=fail on an email that claims to come from a known company is a strong sign of forgery. Also compare the domain letter by letter: look-alike domains pass every check.
Sources and further reading
Public guidance from security agencies and standards bodies.
- IETFRFC 7208: Sender Policy Framework (SPF)
- IETFRFC 6376: DomainKeys Identified Mail (DKIM) signatures
- IETFRFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
- NCSC (UK)Email security and anti-spoofing
- GoogleEmail sender guidelines
- MicrosoftSet up DMARC to validate email in Microsoft 365