22 Sep 20265 minutes read
Email Address Spoofing: What Scammers Can Do with Your Domain

Email address spoofing overview:
- Your email address is enough to impersonate you, unless your domain rejects unauthenticated email.
- SPF and DKIM aren't enough; DMARC alignment and enforcement are what stop spoofing.
- Supply chain impersonation exploits the trust you extend to vendors.
- Credential abuse defeats authentication, since the message is genuinely authorized.
- Auditing SPF, DKIM, DMARC, and your sender inventory closes off exposure.
An attacker doesn't need access to your mailbox to impersonate your company. Your email address alone is enough, unless your domain rejects unauthenticated email. Without authentication controls, any server can claim to send email from any domain. What matters is whether your DNS records are set up to reject unauthenticated email before it reaches an inbox.
This post covers what a scammer can do with your email address, including supply chain impersonation and credential abuse, why SPF, DKIM, and DMARC stop email address spoofing, and how to start auditing your own exposure.
What A Scammer Can Do with Your Email Address
Knowing your email address doesn't give an attacker access to your mailbox. What it gives them is a credible spoofing target. Depending on your authentication configuration, that target might be almost entirely undefended.
Domain Spoofing and Customer-Facing Impersonation
Suppose your organization is a regulated financial services firm. A scammer crafts an email that appears to originate from [email protected], the exact address customers recognize from legitimate invoices. If your DMARC policy is set to p=none, receiving servers still deliver that email. Customers receive it. They act on it.
The attack works not because the scammer has access to your systems, but because your domain doesn't instruct receiving servers to reject unauthenticated email.
Supply Chain Impersonation
Consider a more operationally complex scenario: a vendor account compromise. A scammer gains access to a supplier's email credentials, or simply spoofs that supplier's domain, and begins targeting your procurement or finance team with payment redirection requests. The "From" address is familiar. The domain passes a surface-level check. The request looks routine.
This is where enterprise environments face compounding risk. Large businesses often have dozens of approved vendor relationships, each with its own email-sending setup.
The upstream risk (what happens when a supplier or partner's domain isn't properly authenticated) is as significant as your own domain's exposure. Supply chain impersonation exploits the trust your company extends to third-party senders.
Credential Abuse and Internal Mailbox Compromise
A distinct but related risk is credential abuse. A scammer who obtains a legitimate employee's email credentials through phishing, credential stuffing, or a breach doesn't need to spoof anything. They send from an authenticated mailbox. DMARC passes. SPF passes. DKIM passes.
This is the scenario where authentication alone is insufficient. Once an attacker operates from inside a legitimate sending identity, behavioral signals and mailbox monitoring matter as much as DNS configuration. A compromised internal mailbox often becomes the launchpad for targeting your customers, and it starts with what looks like an authenticated internal send.
Why SPF, DKIM, And DMARC Stop Email Address Spoofing
Authentication protocols don't protect you uniformly. Their effectiveness depends entirely on configuration and enforcement level.
SPF: Necessary But Insufficient Alone
SPF authorizes specific IP addresses to send email on behalf of your domain. The SPF record lists which servers are allowed to send. When a message arrives, the receiving server checks whether the delivering server's IP address is on that list. If it isn't, SPF fails.
The operational problem: SPF checks the envelope sender, not the header "From" address the recipient sees. An attacker spoofing the visible "From" address can evade SPF entirely.
DKIM: Strong But Susceptible
DKIM adds a cryptographic signature to outgoing messages, verified against a public key published in the DNS. A valid DKIM signature confirms the message wasn't altered in transit and originated from an authorized sender.
The enterprise challenge: each sending platform (your marketing automation tool, transactional service, HR system, support platform) that sends email on your behalf needs its own key.
As platforms multiply across departments, key management becomes operationally difficult. Expired keys, missing selectors, or platforms generating unsigned emails create authentication failures that attackers exploit.
DMARC: The Enforcement Layer That Ties Them Together
DMARC does what SPF and DKIM alone can't: it tells receiving servers what to do when authentication fails, and it reports that activity back to the domain owner.
Alignment is the critical concept. DMARC catches spoofing attempts that SPF alone would miss, because it requires the visible "From" domain to match what SPF or DKIM actually authenticated.
But alignment only matters when enforcement is in place.
DMARC has three policy levels:
- p=none - Monitor only. Unauthenticated email is delivered. No protection against spoofing.
- p=quarantine - Failed email goes to Spam or Junk. Partial protection.
- p=reject - Failed email is rejected outright. Full enforcement.
An organization at p=none has DMARC configured but not enforced:
| Host | Type | Value |
|---|---|---|
_dmarc.yourdomain.com | TXT | v=DMARC1; p=none; rua=mailto:[email protected] |
From a spoofing perspective, this policy provides no protection. Attackers who check your DNS records can confirm this before crafting a single fraudulent message. If the result shows p=none, or there's no record at all, your domain is unprotected against email address spoofing.
Auditing Your Exposure to Email Address Spoofing
Start with a sender inventory: every domain and subdomain your business owns, including parked domains and regional variants, and every platform authorized to send on your behalf.
From there, the audit splits into three areas that each warrant their own detailed process:
- SPF configuration - lookup count, redundant records, and whether the final mechanism is
-allor the weaker~all. - DKIM configuration - which selectors are active, which are orphaned, and whether key length meets current standards.
- DMARC reporting and evidence - whether aggregate report data is reviewed, and whether that review is documented well enough to satisfy an auditor.
How Sendmarc Can Help
Sendmarc's DMARC Management Platform is built for the scenarios in this post. It blocks unauthenticated senders behind domain and supply chain impersonation, flags compromised accounts before credential abuse escalates, and keeps your reporting ready for an audit or risk committee.
The platform aggregates DMARC report data across your full domain portfolio, so unauthorized and misconfigured senders surface as part of your normal reporting, instead of during a manual investigation.
Lookalike Domain Defense extends that visibility beyond domains you own, monitoring for lookalike domains built to impersonate your brand.
Breach Detection identifies compromised employee email addresses before they're used for the kind of credential abuse this post describes.
If your own review has surfaced issues (domains at p=none, unknown senders in your aggregate data, or SPF records at the lookup limit), explore Sendmarc's DMARC Management Platform to see how those issues get addressed systematically.



Leave a reply Cancel reply
Your email address will not be published. Required fields are marked *