Email spoofing: how attackers fake your 'from' address
Email spoofing is the forgery at the heart of most phishing: making a message look like it came from someone it did not. It is the reason a scam can appear to arrive from your bank, your CEO, or your own domain. Understanding why it is possible points straight to the fix.
Why email can be faked
Email was built for an open, trusting network. The protocol that sends mail does not, by itself, require the sender to prove their identity — the "from" address is essentially a label the sender writes. So without extra measures, anyone can put your address on a message.
How spoofing powers phishing
- Brand impersonation — a scam that appears to come from a company you trust.
- BEC — a wire-fraud request that looks like it is from your CEO or a supplier.
- Credibility — a spoofed sender makes a malicious link or attachment far more likely to be opened.
A convincing 'from' address does most of a phishing email's work. Remove the ability to forge it and many attacks lose their disguise.
Exact-domain vs lookalike spoofing
There are two flavours. One forges your exact domain — which email authentication can stop. The other uses a lookalike domain (a swapped letter, an extra word) that is technically a different, real domain and therefore passes its own authentication. Each needs a different defence.
Shutting it down
- Authenticate your domain — SPF, DKIM and DMARC at enforcement (reject) stop exact-domain spoofing.
- Monitor for lookalikes — catch the near-identical domains authentication can't cover.
- Take down impersonation — remove the pages and domains used to pose as you.
Phish Plug handles the half authentication can't: the lookalike domains and cloned pages that impersonate you without ever touching your real domain.
The takeaway
Email spoofing exists because the protocol never verified senders. Authentication (SPF, DKIM, DMARC at reject) closes the door on forging your exact domain; monitoring and takedowns handle the lookalikes that slip around it. Together they make your brand hard to wear.
Keep reading
Related articles
Domain monitoring: a practical buyer's guide
What domain monitoring should actually do, the signals that matter, and the questions to ask — so you catch lookalikes early instead of paying for noise.
Read article Best practices · 7 minBrandjacking: when someone hijacks your identity online
Brandjacking covers domains, social handles, ads and apps that seize your identity. The forms it takes and how to reclaim and defend your brand.
Read article Defense · 6 minDoes the padlock mean a site is safe? The HTTPS myth
The padlock means encrypted, not trustworthy. Why most phishing sites now use HTTPS, and what actually tells you whether a login page is real.
Read articleSee your brand's exposure in one pass
Run a free clone check on one domain — lookalikes surfaced, cloaking proven, evidence captured.