Email spoofing is when an email is made to appear as though it came from a different sender.
The name or email address shown in the From field may look familiar or genuine even though the message was sent from somewhere else. This means that seeing a recognised email address does not, by itself, prove that the person or organisation actually sent the message.
Spoofing also does not automatically mean that the real email account was hacked. A sender can imitate an address without gaining access to the real mailbox.
How does email spoofing work?
An email contains information identifying who it claims to be from. Your email service uses that information to show the sender’s name and email address.
However, this displayed information is not the only information available about where the message came from. Email services can also check the system that sent the message and use email authentication to determine whether it was authorised to send email for the domain shown in the From address.
For example, a message could appear to be from:
accounts@example.com
The recipient may recognise the address and assume that the message came from the organisation that owns example.com.
If someone deliberately sends a message through another system while making the From address appear to belong to example.com, that sender identity has been spoofed.
Modern email services can detect many spoofing attempts, although no single check can prove that every message is genuine or safe.
Different ways an email sender can be impersonated
Not every form of email impersonation works in exactly the same way.
Sender-address or domain spoofing makes the From address appear to use an email address or domain that the sender is not authorised to use.
Display-name spoofing copies the name of a trusted person or organisation while using a different email address underneath it.
For example, a message might display:
Accounts Department
but the actual email address belongs to an unrelated sender.
There are also lookalike domains. Someone might register a domain with spelling or characters similar to a genuine domain and send email from it. This is usually better described as domain impersonation rather than technically spoofing the genuine domain, because the message is being sent from a different domain that really exists.
Does a spoofed email mean the account was hacked?
No. A spoofed email address does not, by itself, mean that somebody has accessed the real email account.
A message can be created elsewhere and made to appear as though it came from your address. That is different from somebody gaining access to the real mailbox and sending messages from inside the account.
Evidence such as emails you did not send appearing in your Sent folder or other unexplained activity inside the account would make an actual compromise more likely. An email account can be hacked, but a spoofed From address alone is not proof that this has happened.
Email spoofing vs phishing
Email spoofing and phishing are related, but they are not the same thing.
Spoofing is about making the sender’s identity appear to be something it is not.
Phishing is an attempt to trick someone into doing something unsafe, such as giving away a password, sending money or opening a harmful link or attachment.
A phishing email may use a spoofed address to appear more convincing. However, phishing can also come from a lookalike address or a real email account that has been compromised.
Similarly, an email address can be spoofed without the message necessarily being part of a phishing attempt.
The broader warning signs and methods used in these scams are explained in What Is Phishing and How Can You Spot It?
How can you tell if an email may be spoofed?
There is no single visual check that can prove whether every email is genuine.
However, several things can make a message worth treating cautiously:
- Check the actual email address, not only the sender’s displayed name.
- Look carefully for small differences in the domain name.
- Be cautious if the Reply-To address is different or unexpected.
- Consider whether the request makes sense for the person who supposedly sent it.
- Be careful with unexpected links, attachments or requests for passwords, money or personal information.
- Pay attention to warnings from your email provider about an unverified or unauthenticated sender.
Some email services show warnings when they cannot authenticate a sender. This is a reason for caution, although a message that fails an authentication check is not automatically malicious.
If the message claims to be from someone you know but something seems unusual, contact that person separately. Use a phone number, email address, website or another contact method that you already know is genuine rather than details supplied in the suspicious message.
What should you do with a spoofed or suspicious email?
If you are not confident that the message is genuine, do not reply to it or use links and unexpected attachments inside it.
If necessary, contact the supposed sender separately to check whether they really sent the message.
You can also report suspicious messages using the spam, junk or phishing controls provided by your email service. Once you no longer need the message for reporting or checking, it can be deleted.
If you have already entered a password, sent money or provided sensitive information because of the message, the problem is no longer simply identifying spoofing. Take action to protect the affected account or information.
Can email spoofing be prevented?
Email providers and domain owners can make sender-address spoofing much harder using email authentication.
Three common systems are:
- SPF, or Sender Policy Framework, lets a domain publish which mail servers are authorised to send email on its behalf.
- DKIM, or DomainKeys Identified Mail, adds a digital signature that receiving email services can verify.
- DMARC, or Domain-based Message Authentication, Reporting and Conformance, uses SPF and DKIM results and checks their relationship with the domain shown in the From address. It also lets a domain owner publish a policy for handling messages that fail the required checks.
These systems help receiving email services identify messages that falsely claim to come from a genuine domain. Major email providers use authentication as part of their filtering and anti-spoofing systems.
They do not prevent every type of impersonation. Someone may instead use a misleading display name, register a similar-looking domain or send messages from a legitimate account that has actually been compromised.
For an ordinary email user, there is therefore no setting that can eliminate every spoofed or impersonated message. Email authentication, provider filtering and sensible checks by the recipient work together to reduce the risk.
