TTemp90
T
← Back to BlogPrivacy

What Is Email Spoofing? How to Spot It

Email spoofing explained: how attackers forge sender addresses, why it enables phishing, and how SPF, DKIM, and DMARC help stop it.

What Is Email Spoofing? How to Spot It

What Is Email Spoofing?

Email spoofing is the forging of an email's sender address to make a message appear to come from someone other than the real sender. Because the basic email system was not designed with strong sender verification, attackers can craft emails that appear to come from a trusted person, company, or even your own domain. Email spoofing is a key technique behind phishing and many email scams. This guide explains what spoofing is, why it is possible, how to spot it, and how anti-spoofing technologies help, in plain terms.

Why Email Spoofing Is Possible

Email spoofing exploits a weakness in how email works:

Email's original design: The fundamental email protocols were designed decades ago without built-in strong sender verification. The "From" address can be set by the sender, much like writing any return address on a physical envelope.

Forging the sender: This means an attacker can put a forged sender address on an email, making it appear to come from someone else — a trusted contact, a company, or even your own address.

The trust problem: Because people tend to trust emails based on the apparent sender, spoofing exploits that trust to make malicious emails seem legitimate.

How Spoofing Enables Attacks

Email spoofing is a foundation for various attacks:

Phishing: Spoofed emails appearing to come from trusted companies or people trick recipients into revealing credentials, clicking malicious links, or taking harmful actions.

Business email compromise (BEC): Attackers spoof executives or partners to trick employees into transferring money or sensitive data — a costly form of fraud.

Spreading malware: Spoofed emails appearing trustworthy trick recipients into opening malicious attachments.

Scams: Many scams rely on spoofed senders to appear legitimate.

The common thread is using a forged trusted sender to lower the recipient's guard.

How to Spot Email Spoofing

While spoofing can be convincing, signs can help you spot it:

Check the actual sender address: The display name can be set to anything. Check the actual email address, which may reveal a mismatch or suspicious domain (though the address itself can be spoofed too).

Look for inconsistencies: Mismatches between the display name and address, odd domains, or addresses that are close-but-wrong (typosquatting) are warning signs.

Be wary of unexpected requests: Spoofed emails often make unexpected or urgent requests (for money, credentials, action). Treat these with suspicion regardless of apparent sender.

Verify through another channel: If an email makes an important or unusual request, verify through a separate, known channel (call the person/company directly), not by replying.

Watch for phishing signs: Spoofing usually accompanies phishing, so the usual phishing red flags (urgency, suspicious links, requests for sensitive information) apply.

Don't trust based on sender alone: Since senders can be forged, do not trust an email based solely on who it appears to be from. Verify before acting on important requests.

Anti-Spoofing Technologies: SPF, DKIM, DMARC

Several technologies help combat email spoofing at the domain level:

SPF (Sender Policy Framework): Lets a domain specify which mail servers are authorized to send email for it, so receiving servers can check whether an email claiming to be from that domain came from an authorized server.

DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to emails, letting receiving servers verify the email genuinely came from the domain and was not altered.

DMARC (Domain-based Message Authentication, Reporting and Conformance): Builds on SPF and DKIM, letting a domain specify how to handle emails that fail these checks (e.g., reject or quarantine) and providing reporting.

How they help: Together, these let domains protect their email from being spoofed and let receiving servers detect and filter spoofed emails. When properly configured, they significantly reduce successful spoofing of protected domains.

For domain owners: If you own a domain, configuring SPF, DKIM, and DMARC helps prevent attackers from spoofing your domain and protects your recipients.

Frequently Asked Questions

What is email spoofing in simple terms?

Email spoofing is forging an email's sender address to make a message appear to come from someone other than the real sender — a trusted person, company, or even your own domain. It is possible because the basic email system was designed without strong sender verification, so the "From" address can be set by the sender, like writing any return address on an envelope. Spoofing exploits people's tendency to trust emails based on the apparent sender, making it a key technique behind phishing and email scams.

How can I spot a spoofed email?

Check the actual sender address (not just the display name, which can be anything) for mismatches or suspicious domains, look for inconsistencies and close-but-wrong addresses (typosquatting), and be wary of unexpected or urgent requests for money, credentials, or action. For important or unusual requests, verify through a separate known channel (like calling directly) rather than replying. Since senders can be forged, do not trust an email based solely on who it appears to be from — apply the usual phishing red flags and verify before acting.

What are SPF, DKIM, and DMARC, and how do they help?

They are email authentication technologies that combat spoofing at the domain level. SPF specifies which mail servers are authorized to send email for a domain. DKIM adds a cryptographic signature so receivers can verify an email genuinely came from the domain and was not altered. DMARC builds on both, letting a domain specify how to handle emails that fail these checks and providing reporting. Together, when properly configured, they let domains protect their email from being spoofed and help receiving servers detect and filter spoofed messages.

Conclusion

Email spoofing is the forging of an email's sender address to make a message appear to come from someone other than the real sender, exploiting the fact that the basic email system was designed without strong sender verification — the "From" address can be set like any return address on an envelope. Spoofing exploits people's tendency to trust emails based on the apparent sender, making it a foundation for phishing, business email compromise, malware spread, and scams. You can spot it by checking the actual sender address for mismatches, being wary of unexpected or urgent requests, verifying important requests through a separate known channel, and never trusting an email based solely on who it appears to be from. At the domain level, anti-spoofing technologies — SPF, DKIM, and DMARC — let domains protect their email from being spoofed and help receivers detect and filter forged messages, making them valuable for any domain owner to configure. By understanding how email spoofing works, staying alert to its signs, and supporting domain-level authentication, you can protect yourself from the attacks that forged senders enable.

More from Temp90

Privacy resources made simple

FAQCommon temporary email questions. Trust CenterService status and transparency. Privacy PolicyHow Temp90 protects privacy. Terms of UseRules for using Temp90 safely.