Email sender spoofing explained
Why the 'From' address on an email can be forged, and what actually verifies a sender.
By AlertaSpam Security Team. Published August 7, 2026
The basic email protocol does not require the 'From' address to be authenticated, which historically made it trivial to send a message that appears to come from any address at all. This is distinct from a look-alike domain (a real but different domain designed to resemble a brand) — true spoofing forges the address itself.
Three technical standards now exist specifically to catch this: SPF, DKIM, and DMARC. Most major mail providers check incoming mail against them and will show a warning, or route the message to spam, when a message fails — but not every organization has these fully configured, so their absence doesn't clear a message either.
In webmail clients, look for an added 'via' or 'on behalf of' label next to the sender name — this often indicates the message didn't originate cleanly from the claimed domain, though it can also appear for legitimate mailing services.
As with any suspicious message, the reliable response is not to reply to it or click its links, but to contact the supposed sender through a separate, already-trusted channel.
