Email

What is email spoofing and how can I prevent it?

Updated

Email spoofing is when someone sends an email with a forged “From” address so it appears to come from you, your business or someone you trust. The message itself might be a scam, a fake invoice, or a link that installs something nasty. Because the sender name looks right, people open it.

How spoofing works

Email was designed in an era when nobody imagined it would be abused. The protocol that carries mail (SMTP) does not check that the address in the “From” line belongs to the server sending it. Anyone with a mail server can type any address they like. Unless the receiving server has a way to check, the message lands looking genuine.

Two things make spoofing of your own domain much harder: telling the world which servers are allowed to send mail for your domain, and signing the mail you send so a receiver can verify it has not been tampered with.

The three records that protect your domain

All three live in your domain’s DNS, next to the records that point your website and your mail. We set these up for every client on managed hosting.

  1. SPF (Sender Policy Framework). A text record listing the servers allowed to send mail for your domain, for example Google Workspace and your website’s transactional mail service. A receiver checks the sending server against the list.
  2. DKIM (DomainKeys Identified Mail). Your mail provider signs every outgoing message with a private key. The matching public key sits in your DNS, so the receiver can confirm the message really came from your provider and was not altered in transit.
  3. DMARC (Domain-based Message Authentication, Reporting and Conformance). A policy record that tells receivers what to do when a message fails SPF and DKIM: monitor it, send it to spam, or reject it outright. DMARC also sends you reports so you can see who is sending mail in your name.

With all three in place and a DMARC policy of “reject”, Gmail, Outlook and most business mail systems will refuse mail that pretends to be you.

What to do if someone is spoofing you

  • Check that SPF, DKIM and DMARC exist for your domain. If you are on our hosting, ask us to confirm them.
  • Move DMARC from “none” (monitor only) to “quarantine” and then “reject” once your legitimate senders all pass.
  • Warn your customers and staff not to act on unexpected requests for payment or passwords, even from a familiar address, without confirming by phone.
  • Never host email on the same box as your website. Use a major provider such as Google Workspace, which handles signing and reputation properly.

What spoofing is not

Spoofing is not the same as a hacked mailbox. If someone has your password, they are sending real mail from your real account and no DNS record will stop it. Change the password, turn on two-step verification, and check the mailbox for forwarding rules you did not create.

If you are unsure where your domain stands, get in touch and we will check the records for you.

Related articles

  1. 01

    How to add an Administrator to your Google domain

    Need to give Shipwreck Studio admin access to your Google Workspace? Step by step instructions to create a new admin user on your domain, and what it costs.

  2. 02

    What is the difference between POP3 and IMAP protocols? (In English!)

    Setting up email and asked to choose POP3 or IMAP? A plain English side by side comparison: devices, folders, syncing, speed and which one keeps your mail safe.

Back to the knowledge base