DMARC Engine
Home/Glossary/Email spoofing
Glossary

Email spoofing

Forging a message's sender so it appears to come from a domain or person it does not, used in phishing and fraud.

Email spoofing is the forging of sender information so a message appears to originate from a trusted domain or individual. Because the SMTP protocol does not, by itself, verify who is sending, an attacker can place any address in the visible From header and in the Return-Path. Recipients then see a familiar brand or colleague and act on the message.

Spoofing underpins phishing and business email compromise, where a forged invoice or payment request looks exactly like the real thing. There are several variants: exact-domain spoofing reuses your real domain, while display-name spoofing and lookalike domains imitate it without controlling it.

The defence against exact-domain spoofing is email authentication. SPF and DKIM let receivers verify the sending source, and DMARC ties those checks to the visible From domain and tells receivers to reject or quarantine messages that fail. At an enforcement policy of p=reject, a forged message claiming to be your domain is dropped before it reaches an inbox. DMARC Engine moves domains to that enforced state safely. To see whether your domain can currently be spoofed, run a DMARC check and confirm the policy is not merely p=none.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.