Email Spoofing
Forging the sender address of an email so it appears to come from a trusted person or domain, typically by exploiting a domain that lacks proper SPF, DKIM, and DMARC protections.
Definition
Email spoofing is the act of forging the sender information in an email, typically the visible 'From' name and address or the underlying envelope sender, so that a message appears to come from a trusted colleague, executive, or well-known brand when it was actually sent by an attacker. It works because the original email protocol, SMTP, was never designed to verify who is actually sending a message, and it remains possible today wherever a receiving domain has not deployed authentication standards that check sender legitimacy.
Spoofing exploits the gap between what a mail server technically allows and what a domain owner actually intends. Without protective DNS records in place, anyone can configure an outgoing mail server to display any 'From' address they choose, including one that matches a real company's domain exactly, and many receiving mail systems will deliver the message without complaint. This is what makes spoofed emails so convincing: recipients see a familiar sender name and domain in their inbox and have no easy way to tell, just by looking, that the message did not actually originate from that organization's real mail infrastructure.
Spoofing is the technical mechanism behind a large share of business email compromise and brand impersonation attacks, since a spoofed email claiming to be from a CEO or a known vendor is far more persuasive than an email from an obviously unrelated address. Indonesian organizations that have not fully deployed SPF, DKIM, and DMARC on their domains remain exposed both as spoofing targets, where their own domain is forged to attack customers or partners, and as spoofing victims, where attackers impersonate other trusted brands to target their staff.
The defense is largely a DNS configuration exercise: SPF (Sender Policy Framework) publishes which mail servers are allowed to send on a domain's behalf, DKIM (DomainKeys Identified Mail) cryptographically signs outgoing mail so recipients can verify it was not altered, and DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the two together and tells receiving servers what to do with messages that fail these checks, ideally reject or quarantine them. Deploying all three, moving DMARC from monitoring mode to an enforced reject policy, and training employees to check sender domains carefully together close most of the gap that makes email spoofing possible.
At a glance
- Severity
- High
- Prevalence
- Very common
- Primary targets
- Any domain without enforced SPF, DKIM, and DMARC
How it works
- 1
Domain selection: an attacker chooses a trusted brand, executive, or vendor domain to impersonate, ideally one without strict email authentication.
- 2
Header forgery: the attacker configures an outgoing mail server or spoofing tool to display a 'From' address matching the trusted domain or name.
- 3
Delivery: without SPF, DKIM, and DMARC enforcement on the impersonated domain, the recipient's mail server delivers the message without flagging it.
- 4
Deception: the recipient sees a familiar sender name and domain in their inbox and is far more likely to trust the message's request.
- 5
Exploitation: the spoofed email is used to harvest credentials, request a fraudulent payment, or deliver malware under the cover of a trusted identity.
Warning signs
- A 'reply-to' address that differs from the displayed sender address
- Urgent or unusual requests, such as payment changes or gift-card purchases, from an executive's apparent email
- Slight inconsistencies in tone, signature, or formatting compared to how the sender usually writes
- Email authentication warnings your mail client displays about the message failing SPF, DKIM, or DMARC checks
- A request to bypass normal approval processes 'just this once' for an unusual transaction
How to defend
- Publish and correctly configure SPF records to specify which servers may send on your domain's behalf
- Deploy DKIM to cryptographically sign outgoing mail so recipients can verify authenticity
- Deploy DMARC and move from monitoring mode to an enforced reject or quarantine policy once safe to do so
- Train employees to verify the sending domain, not just the display name, before acting on unusual requests
- Verify any payment or credential-related request through a second channel, such as a phone call to a known number
- Monitor DMARC reports to detect and respond to attempts to spoof your own domain
Real-world example
Staff at an Indonesian trading company receive an email that appears to be from their finance director asking for an urgent bank transfer to a new supplier account. The display name and signature match perfectly, but the domain lacks a DMARC enforcement policy, so the message, actually sent by an attacker who forged the From address, is delivered without warning, and a junior finance officer nearly completes the transfer before double-checking by phone.
How Claro helps
Claro's phishing simulations replicate spoofed sender scenarios so employees learn to scrutinize the actual sending domain rather than the display name, while the platform's guidance for tenant sending domains reinforces SPF, DKIM, and DMARC best practice, helping Indonesian organizations close the exact gap spoofing exploits on their own mail infrastructure.
Frequently asked questions
Is email spoofing the same as hacking an email account?
No. Spoofing forges the sender information on a message sent from an attacker's own infrastructure, and the real account is never actually compromised. Account takeover, by contrast, means the attacker has genuinely broken into and is sending from the real account.
How can I tell if an email is spoofed?
Check the actual sending domain and reply-to address rather than just the display name, and look for your mail client's authentication warnings about failed SPF, DKIM, or DMARC checks. When in doubt, verify unusual requests through a separate channel.
What do SPF, DKIM, and DMARC actually do?
SPF lists which mail servers are authorized to send for a domain, DKIM cryptographically signs messages so tampering can be detected, and DMARC tells receiving servers what to do with messages that fail those checks, ideally rejecting or quarantining them.
Can email spoofing be completely prevented?
A domain owner cannot stop attackers from attempting to spoof their domain, but a properly enforced DMARC policy at reject means spoofed messages claiming to be from that domain will not reach recipients' inboxes at all.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Brand Impersonation
A phishing tactic where attackers mimic a well known company's branding, tone, and communication style to make fraudulent messages appear legitimate.
Business Email Compromise
A targeted financial fraud where an attacker poses as a trusted executive, supplier, or colleague over email to trick an employee into transferring money or sensitive data.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo