Spoofing: prevent someone from mailing in your name

What is email spoofing?
Spoofing is forging the sender of an email. Someone sends a message that appears to come from you@yourbusiness.com, while you have nothing to do with it. The sender field of an ordinary email is, after all, just as easy to fill in as the sender on an envelope: you can put whatever you like on it.
Spoofing is often used for phishing and fraud: customers or colleagues get a "genuine-looking" message from you, with a fake account number or an infected attachment. You sometimes notice little of it yourself, until someone calls you about a mail you never sent. It goes hand in hand with phishing, where the fake sender makes the bait believable.
Why preventing email spoofing matters
If your domain is misused, the damage is twofold. Your customers can be scammed in your name, and your reputation and deliverability take a hit: if a lot of fake mail circulates from "your" domain, receiving servers start to distrust your genuine mail too.
For an accountant, doctor or SME that runs on trust, that's a real risk. One fraudulent invoice "from you" can cost a customer thousands of euros and damage your relationship. So combating spoofing protects not only you, but everyone who receives mail from your domain.
There's one more distinction that clears up confusion. In genuine spoofing the attacker uses your exact domain in the sender address; that's precisely what SPF, DKIM and DMARC can lock down. In impersonation they use a look-alike domain name (for example with an extra letter or a different extension) that isn't yours. Your own authentication doesn't help against that second form, because it isn't about your domain. It's good to know that distinction, so you know which part is within your control and which part calls for vigilance.
How it works
On the community security.nl the core question came up strikingly: do DKIM and DMARC really help against spoofing? The short answer: yes, provided you use them together. Three arrangements work together here, each with its own role.
- SPF records in your DNS which servers may send on behalf of your domain. The recipient checks whether a message comes from such an allowed server.
- DKIM puts a digital signature on your outgoing mail. The recipient checks that signature and thus knows the message really comes from your domain and wasn't altered along the way.
- DMARC binds it all together. It tells the recipient what to do if SPF or DKIM doesn't check out: do nothing, put it in spam, or reject it outright. DMARC also ensures that the visible sender address must match what SPF and DKIM prove (that's called alignment).
That last step is exactly what makes the difference against spoofing. SPF and DKIM on their own say nothing yet about the visible "from" address the recipient sees. Only with DMARC do you demand that a spoofer posing as your domain gets caught and rejected. If you want to understand exactly what DMARC does, read what DMARC is. Setting them up together is covered step by step in setting up SPF, DKIM and DMARC together.
What to watch out for
- DMARC starts gently. You usually begin with a policy that only reports (
p=none), so you can see who sends on your behalf before you tighten up to quarantine or reject. - Don't forget legitimate senders. If a newsletter service or accounting package sends on your behalf, they must be included in SPF and DKIM, otherwise you accidentally block your own mail.
- Eradicating spoofing completely isn't possible. You make misuse of your domain far harder, but attackers can still switch to look-alike domains. So keep watching for phishing signals too.
- Maintenance counts. If your sending infrastructure changes, your records must follow. Outdated records are themselves a source of problems.
- It affects your deliverability. Correct authentication not only helps against spoofing, but also ensures your own mail arrives better, as described in why mail ends up in spam.
One more practical point: use the DMARC reports you get back. As soon as DMARC is active, receiving servers send overviews of everyone who sends on behalf of your domain. That way you not only see misuse attempts, but also discover legitimate services you still need to add, before you tighten the policy. Reading those reports takes some getting used to, but they give you exactly the insight to shut down spoofing in a targeted way without blocking your own mail.
And at Mailflux
At Mailflux we manage SPF, DKIM and DMARC for your domain, so forged messages in your name are far harder to get through and your own mail carries the right signals. You don't have to dive into DNS records yourself; we keep them up to date whenever something changes.
On top of that, every plan filters with machine learning against spam, phishing and malware, with standard antivirus, antispam and antimalware, automatic backups and optional two-step verification. You get professional email on your own domain, hosted in Europe and GDPR-compliant.
FAQ
Frequently asked questions
Do DKIM and DMARC really help against spoofing?
Yes, but together. DKIM signs your mail so forgery stands out, and DMARC forces the visible sender address to match what SPF and DKIM prove. Without DMARC the "from" address stays easy to forge; with a strict DMARC policy spoofing of your domain is rejected.
Can I stop spoofing completely?
You make misuse of your own domain far harder with SPF, DKIM and a strict DMARC policy. Ruling it out entirely isn't possible: attackers switch to look-alike domain names that aren't yours. That's why alertness from you and your recipients remains an indispensable addition to the technology.
Someone is mailing in my name, what do I do?
First check that your SPF, DKIM and DMARC are set up correctly and tighten DMARC if needed. Warn affected contacts that fake mail is circulating. If you notice it involves a look-alike domain rather than your own address, then it's impersonation and awareness helps most.