Skip to content
Skip to main content
Email Evidence Technical Explainer

What if the email address was spoofed?

Spoofing means the identity presented to the recipient does not reliably identify the account or system that submitted the message. The display name, a lookalike address or even the exact From address can be asserted without using the genuine mailbox.

Test presentation against the trusted route

Preserve the native message, expand the full From address and compare its domain with Reply-To and Return-Path. Work from the recipient's trusted Received chain to identify the external sending system. Authentication-Results added inside that boundary can show SPF, DKIM and DMARC outcomes.

DMARC alignment can support an authorised route for the displayed domain; it still does not identify an individual. Failures can reflect forwarding or misconfiguration, so the result needs route and organisational context.

Separate spoofing from genuine-account misuse

With spoofing, the attacker presents another identity. With compromise, the real provider account may send and authenticate normally under another controller. Ask the claimed organisation whether it recognises the message or platform and seek provider trace and account evidence.

Report that the displayed identity lacks support from the trusted route before attributing who forged it or why.

The point to remember

Spoofing is tested by comparing the presented identity with trusted delivery and domain-authentication evidence.

Sources

Reference: EML-026Email Evidence