Email spoofing is the practice of making an email appear to come from a trusted person or organization by manipulating sender identity information.
Why can spoofing be effective?
Recipients often look first at the displayed sender name. Attackers may use the name of an executive, supplier or known company to make a message look legitimate.
Display name and actual address may differ
A message can show a familiar display name while the underlying sender address belongs to an unrelated domain.
What is domain spoofing?
Some attacks attempt to imitate not only a person’s name but also the company’s domain identity, which is why domain authentication is important.
How do SPF, DKIM and DMARC help?
These mechanisms help receiving systems evaluate whether a message originated from an authorized source. DMARC also evaluates alignment with the domain visible in the From address.
What should users do?
Payment requests, password-reset messages and unusual instructions should never be trusted solely because the sender name looks familiar.
Read our DMARC guide to learn more.