technical · sourced answer
Email Spoofing: Definition and Technical Mechanisms
Email spoofing is the act of forging an email header so that the message appears to have originated from a legitimate or known source. Because the Simple Mail Transfer Protocol (SMTP) does not inherently validate the From address, any sender can specify any identity in the message envelope or header.
Mechanical Process
Spoofing occurs during the SMTP transaction. The protocol separates the envelope sender (MAIL FROM) from the header sender (From:). A malicious actor can connect to an open relay or use a custom script to specify a trusted domain in the From header while using a different return path. The receiving mail server, by default, processes the message based on these provided strings without verifying if the sending IP is authorized to use that domain.
Impact on Legitimate Senders
When attackers spoof a domain, they damage the reputation of the legitimate owner. High volumes of spoofed phishing emails can lead to the domain being blacklisted by global filters. This results in legitimate transactional and marketing emails being flagged as spam or rejected entirely. Maintaining a strict authentication posture is the only way to signal to receivers that unauthorized mail should be discarded.
Prevention via Authentication
Prevention relies on three pillars: SPF, DKIM, and DMARC. SPF lists authorized IP addresses. DKIM adds a cryptographic signature to the header. DMARC ties these together, instructing the receiver to reject or quarantine mail that fails these checks. You can use SendHQ free tools (https://sendhq.cc/tools) to verify if your current DNS records are correctly configured to block spoofing attempts.
Operational Mistakes
A common error is configuring an SPF record as SoftFail (~all) instead of Fail (-all) while lacking a DMARC policy. This tells receiving servers that the mail is likely unauthorized but should still be accepted. Another mistake is failing to update SPF records after migrating to a new ESP, which causes legitimate mail to look like spoofed traffic to the receiving server.
Concrete Example
An attacker sends an email where the SMTP envelope is set to attacker@malicious.com but the header is set to From: billing@yourcompany.com. If yourcompany.com has no DMARC policy, the recipient's mail client displays the billing address, tricking the user into believing the request is official, even though the underlying transport was unauthorized.
Questions teams ask
Is spoofing the same as phishing?
No. Spoofing is the technical method of forging the sender identity. Phishing is the social engineering goal of the attack, which often uses spoofing as a tool to gain trust.
Can SPF alone stop spoofing?
No. SPF only validates the envelope sender. Attackers can use a valid envelope from their own domain while spoofing the visible From header. DMARC is required to ensure header alignment.
Does DKIM prevent spoofing?
DKIM proves the content was not altered and came from a domain owning the key, but it does not prevent a sender from omitting the signature entirely unless a DMARC policy mandates it.
Primary sources
- RFC 5321: Simple Mail Transfer Protocol — RFC Editor
- RFC 7489: Domain-based Message Authentication, Reporting and Conformance — RFC Editor
- RFC 7208: Sender Policy Framework — RFC Editor