Definition
Email spoofing is the creation of email messages with a forged sender address, making the email appear to originate from someone or somewhere other than the actual source. Spoofing exploits the inherent vulnerability of the Simple Mail Transfer Protocol (SMTP), which does not include built-in authentication mechanisms. Attackers can manipulate the SMTP envelope headers and the RFC 5322 From header to display any address they choose. According to the 2024 Verizon Data Breach Investigations Report, 36 per cent of all data breaches involved phishing, with spoofed email being the primary delivery mechanism. The Anti-Phishing Working Group reported over 5 million phishing attacks in 2023, the majority using some form of sender address forgery.
Spoofing is prevented through a three-layer email authentication framework. Sender Policy Framework (SPF) allows domain owners to publish DNS records specifying which IP addresses are authorised to send mail from their domain. DomainKeys Identified Mail (DKIM) adds a cryptographic digital signature to message headers, enabling receiving servers to verify that the message was not tampered with in transit. Domain-based Message Authentication, Reporting, and Conformance (DMARC) builds on SPF and DKIM by instructing receiving servers how to handle messages that fail authentication checks — typically quarantine (spam folder) or reject (block). Google reported in 2024 that DMARC enforcement reduced spoofing of Gmail-addressed messages by 65 per cent for domains implementing a reject policy.
For email marketers, spoofing poses a unique reputational risk. When your domain is spoofed and used to send malicious messages, receiving mailboxes may begin associating your legitimate marketing emails with spam or phishing classifications. This collateral damage can depress deliverability rates for months, even after the spoofing attack has been contained. According to a 2023 Validity report, 22 per cent of brands experienced domain spoofing in the previous 12 months, and those that did not have DMARC enforcement in place saw an average 15 per cent decline in inbox placement rates for their legitimate marketing campaigns.
Best Practices
Implement DMARC at a monitoring policy (p=none) first to understand your email authentication landscape without affecting delivery. Analyse DMARC aggregate reports using a service like Postmark, Mimecast, or a dedicated DMARC analytics platform to identify all legitimate sources sending mail from your domain — including your ESP, CRM, transactional email provider, and any third-party platforms. This discovery phase typically takes 30 to 90 days depending on traffic volume.
Once you have identified all authorised senders, publish a strict SPF record that explicitly lists every permitted sending IP address and prevents unauthorised servers from passing SPF checks. Keep your SPF record under the DNS lookup limit of 10 addresses, using SPF macros or include mechanisms where necessary. Each ESP or third-party vendor will typically provide the include statement you need to add to your SPF record.
Configure DKIM signing for every email-sending platform you use, generating a separate DKIM selector for each service. This allows you to revoke signing authority for a compromised or decommissioned platform without affecting other senders. Rotate your DKIM keys annually as recommended by most mailbox providers, and ensure your DNS TTL values are set low enough to facilitate quick key rotation during a security incident.
Progress your DMARC policy from p=none to p=quarantine and finally to p=reject once you have verified that all legitimate email sources are authenticating properly. A reject policy provides the strongest protection against spoofing because receiving servers will block messages that fail SPF and DKIM checks rather than delivering them to spam folders. Google and Yahoo now require DMARC enforcement for bulk senders sending over 5,000 messages per day to their domains.
Monitor DMARC failure reports (ruf) and aggregate reports (rua) continuously, setting up automated alerts for unexpected authentication failures that may indicate either a spoofing attack or a misconfigured legitimate sender. Use BIMI (Brand Indicators for Message Identification) alongside DMARC enforcement to display your verified brand logo in supported email clients, further protecting your brand identity and building subscriber trust.
Related Glossary Terms
Bounce Classification
Bounce classification uses SMTP codes (550, 551, 552, 553, 554, 450, 451, 452) and enhanced status codes to categorise permanent and transient delivery failures.
DMARC Alignment
DMARC identifier alignment determines whether the domain in the From header matches the domains used in SPF and DKIM authentication. Strict or relaxed.
DMARC Policy Tags
DMARC DNS record tags including v, p, sp, rua, ruf, pct, adkim, aspf, fo, rf, and ri control authentication policy, reporting, and alignment enforcement.
Email Active Subscriber
An active email subscriber has opened or clicked an email within a defined recency period, typically 30-90 days by industry. Active subscriber rate of 40-60% is typical for healthy email lists.
Email BIMI VMC
BIMI Verified Mark Certificate (VMC) certifies brand logo ownership for display in supporting email clients. VMCs cost £1,500-2,000+ per year per logo and require DMARC reject or quarantine policy plus SVG logo format.
Email Blacklist
An email blacklist (DNSBL) is a real-time database of IP addresses or domains known for sending spam or unwanted email.
Frequently Asked Questions
Check DMARC aggregate reports for authentication failures from unknown IP addresses. Monitor your email bounce rates for sudden increases, as spoofed messages generate non-delivery receipts sent to your real domain. Subscribers may also forward suspicious messages to your abuse desk.
DMARC prevents exact-domain spoofing — messages that forge your exact domain in the From header. It does not prevent lookalike domains, display name spoofing, or cousin domains where attackers register similar domains such as yourbrand-security.com.
Mailbox providers may begin treating all messages from your domain with suspicion, routing legitimate marketing emails to spam folders. Recovery requires proving your sending practices are legitimate, which can take weeks or months depending on the volume and duration of the spoofing attack.
Most organisations take three to six months to progress from p=none to p=reject. The timeline depends on the number of systems sending email from your domain and how quickly you can configure SPF and DKIM for each authorised sender.
BIMI allows brands to display a verified logo next to their authenticated emails in supported email clients. BIMI requires DMARC enforcement at p=quarantine or p=reject, creating an additional incentive for strong email authentication and helping subscribers distinguish legitimate messages from spoofed ones.