A supplier forwards you an email, apparently from your accounts team, asking them to update your bank details. Nobody on your team sent it. Someone used your domain in the From address, and the email system let them. Effective email spoofing prevention is mostly a matter of DNS configuration that many businesses have never completed, plus some awareness of the tricks that DNS alone cannot stop. This article covers both.
Why spoofing is possible at all
The core email protocol, SMTP, was designed without any built-in check that the sender is who they claim to be. The From address is just text the sending software writes into the message, much like the return address on a paper envelope. Anyone running a mail server, or a script, can put your domain there.
Protection therefore has to be added on top: you publish rules about your domain, and receiving servers enforce them.
The four kinds of spoofing
| Type | Example From line | Stopped by DMARC? |
|---|---|---|
| Exact-domain spoofing | accounts@example.com | Yes, at p=quarantine or p=reject |
| Subdomain spoofing | billing@pay.example.com | Yes, if the subdomain policy is enforced |
| Lookalike domain | accounts@examp1e.com | No, it is a different domain |
| Display name spoofing | "Example Accounts" <randomuser@freemail.test> | No, your domain is not used |
Your DNS settings control the first two completely. The last two need different measures, covered further down.
Stopping exact-domain and subdomain spoofing
1. Publish SPF
A TXT record at your domain listing the servers allowed to send for it, for example v=spf1 include:_spf.google.com ~all. On its own, SPF checks only the hidden envelope sender, not the visible From address, so it is a building block rather than a solution.
2. Sign with DKIM
Enable DKIM signing using your own domain on every service that sends as you. A valid signature proves the message was authorised by your domain and not altered.
3. Enforce DMARC
DMARC is what actually protects the visible From address. It requires SPF or DKIM to pass for a domain that matches the From domain, and tells receivers what to do when neither does. At p=none you get reports but no protection. The protection begins at p=quarantine and is strongest at p=reject:
_dmarc.example.com. TXT "v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@example.com"
The sp=reject tag extends the same policy to subdomains that do not publish their own record, so anything.example.com cannot be abused either.
Move to enforcement carefully: start at p=none, use the reports to find and fix every legitimate sender, then step up. Our SPF, DKIM and DMARC checker shows where your domain currently stands.
4. Protect domains that never send email
Spoofers love parked or secondary domains because nobody watches them. For every domain you own that does not send mail, publish:
example.net. TXT "v=spf1 -all"
_dmarc.example.net. TXT "v=DMARC1; p=reject; sp=reject"
example.net. MX 0 .
That declares no authorised senders, rejects any mail claiming to be from the domain, and (with the null MX) states that it accepts no mail either. A WHOIS lookup on each of your domains is a good way to build the list.
Dealing with lookalike domains
An attacker can register a domain that looks like yours, swapping a letter, adding a hyphen or using a different extension, and set up perfect SPF, DKIM and DMARC for it. Your DMARC policy does not apply to their domain. Defences include:
- Defensive registration of your most obvious variations and key country extensions, then locking them down as non-sending domains.
- Monitoring new domain registrations for names similar to yours; several commercial services do this.
- Takedown requests to the registrar and host when a lookalike is used for fraud, and trademark dispute procedures where appropriate.
- Inbound filtering that flags messages from newly registered or lookalike domains.
Dealing with display name spoofing
Here the attacker uses your company or a manager's name with an unrelated address. Many mail apps, especially on phones, show only the display name, so it works surprisingly well. Countermeasures are on the receiving side:
- Turn on your mail platform's impersonation protection for key staff names and your company name, where available.
- Add a visible banner to messages from external senders, so a "CEO" email from outside stands out.
- Train staff to check the actual address, not just the name.
Process controls matter as much as DNS
Most spoofing attacks against businesses aim at payments: changed bank details, urgent transfers, gift card requests. Technical controls reduce how many such messages arrive; process controls make the ones that slip through harmless. Require a phone call to a known number before changing supplier bank details, use two-person approval for payments above a threshold, and make it normal for staff to question unusual requests from senior people. Tell your customers and suppliers how you will and will not contact them about payments.
Checking that it works
After enforcing DMARC, review aggregate reports for unauthorised sources being rejected, and confirm your legitimate mail still shows dmarc=pass in message headers. Re-check after adopting any new tool that sends email on your behalf.
Key takeaways
- SPF and DKIM are building blocks; DMARC at quarantine or reject is what stops exact-domain spoofing.
- Set
sp=rejectand lock down every non-sending domain you own. - Lookalike and display name spoofing need monitoring, inbound filtering and staff awareness.
- Verification procedures for payments protect you when a spoofed email gets through.