TL;DR: Email spoofing lets a scammer send messages that look like they came from your domain, usually to trick a client into paying a fake invoice. Three DNS records (SPF, DKIM, and DMARC) prove your mail is really yours. The catch is that DMARC only blocks anything once it’s set to quarantine or reject, and most businesses stop at monitoring. Check your domain, then roll enforcement out in stages.
Right now, with no hacking and no special tools, a stranger could send an email that looks like it came from your company. Your domain in the From line, your logo pasted in, and a note asking a client to update banking details. That’s email spoofing.
Here’s the part that catches owners off guard: the target usually isn’t you. It’s your client, your supplier, or a bookkeeper who trusts your name. Nothing on your network has to be compromised for this to work. You find out when someone calls asking why the wire went to the wrong account.
The money is real. The FBI’s 2025 Internet Crime Report put business email compromise losses at $3.04 billion for the year, and phishing and spoofing was the single most reported crime type.
Three DNS records make this much harder to pull off. They’re called SPF, DKIM, and DMARC. Most businesses have one or two of them in place and the third missing or half-configured, which is usually all it takes to let a spoofed message through.
Why Can Someone Send Email Using Your Company’s Name?
Email was built without sender verification. The From address is about as trustworthy as the return address handwritten on an envelope: anyone can write anything there, and the mail still gets delivered. Unless your domain publishes records that say otherwise, a receiving server has no reason to question it.
That’s a design gap from a more trusting era, not a break-in. Your Microsoft 365 tenant can be locked down tight and someone can still put your domain in the From field of a message sent from their own server. The UK’s National Cyber Security Centre publishes anti-spoofing guidance for exactly this reason, and treats authentication as a baseline rather than an upgrade.
The Three Records That Stop Email Spoofing
Three DNS records work together to prove a message really came from you. You add them once, at your domain registrar or DNS host, and receiving mail servers check them on everything you send. Together they’re the foundation of any serious email and spam protection setup.
SPF: the guest list
SPF (Sender Policy Framework) is a published list of the mail servers allowed to send email for your domain. When a receiving server gets a message claiming to be from you, it checks whether the sending server is on that list. A server that isn’t on the list gets flagged.
DKIM: the wax seal
DKIM (DomainKeys Identified Mail) adds a tamper-proof signature to every message you send. Your mail server signs outgoing email with a private key, and the matching public key lives in your DNS. The receiving server checks the signature to confirm two things: the message came from your domain, and nobody altered it in transit.
DMARC: the instruction to the doorman
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the other two together and tells receiving servers what to do when a message fails. It also confirms the domain in the visible From address matches the one SPF and DKIM verified, which is the part that stops someone forging your exact address. It sends you reports too, showing everyone sending email as your domain, including the senders who shouldn’t be.
What Is the DMARC Setting Most Businesses Get Wrong?
The policy tag. DMARC has three settings, and p=none only monitors. It tells receiving servers to deliver failing mail anyway and send you a report, so your domain can still be spoofed. Real protection starts at p=quarantine and finishes at p=reject.
Here’s how the three break down.
- p=none does nothing when a message fails. You get reports and no protection.
- p=quarantine sends failing messages to the junk folder.
- p=reject blocks failing messages before they arrive at all.
Now the uncomfortable part. EasyDMARC’s 2026 adoption report found roughly 938,000 domains with valid DMARC records in early 2026, and more than 525,000 still sitting at p=none. Over half of everyone who bothered to set this up is getting reports and nothing else. A Red Sift analysis of 73.3 million domains in late 2025 found it’s worse at scale: nearly 84% had no DMARC record at all.
“We have DMARC” and “we’re protected from spoofing” are two different statements, and plenty of businesses have been told the first while assuming the second.
What SPF, DKIM, and DMARC Don’t Stop
These records stop someone from forging your exact domain. Two things get past them, and both show up constantly in real fraud attempts.
Lookalike domains. A scammer registers something close to yours, like yourcompany-invoices.com, or .co instead of .com. It passes authentication perfectly, because they own it and configured it correctly. Your records protect your domain, not one an attacker bought last Tuesday. A February 2026 study found more than 28,000 registered lookalike domains across just 20 major brands.
Display-name spoofing. The name in the From line reads “Your Company Accounts” while the actual address behind it is a random Gmail account. DMARC checks the domain, not the display name.
For both of those, the defense is people. Check the full email address rather than the display name, and verify any request to change payment details by calling a number you already have, never one printed in the email. That’s exactly what ongoing security awareness training is for.
Why This Matters Even If You Don’t Send Bulk Email
Two reasons, and the second one surprises people. The first is protection: these records keep scammers from impersonating your domain to your clients, your vendors, and your own staff.
The second is deliverability. Google and Yahoo have required SPF, DKIM, and DMARC from bulk senders since February 2024, meaning anyone sending more than 5,000 messages a day. Microsoft applied similar rules to Outlook.com, Hotmail, and Live in May 2025, first routing non-compliant mail to junk and then rejecting it outright.
You may never touch 5,000 messages a day. It still matters, because every mailbox provider now treats these records as a trust signal, and a clean domain is more likely to land in the inbox than the spam folder.
How Do You Check Your Own Domain?
You can find out in about a minute. Our free DMARC, DKIM, and SPF scanner checks all three records for your domain and shows you what’s published, what’s missing, and where you stand on deliverability. No call required.
When you get the result, the number to look for is your DMARC policy. If it reads p=none, you have monitoring and nothing more. If there’s no DMARC record at all, anyone can send as you today.
One caution worth naming. A scan tells you what’s published, not whether it’s correct. An SPF record missing your CRM, or a DKIM key never rotated after a mail migration, still shows up as present. The scan is the start of the conversation, not the end of it.
What Does a Safe Rollout Look Like?
Three stages. Publish SPF and DKIM covering every system that sends mail as you. Add DMARC at p=none and read the reports for a few weeks to confirm your real mail passes. Then move to quarantine, then to reject. Skipping ahead is what sends your own invoices to spam.
Microsoft’s own guidance follows this same path: start at none, verify, and work toward reject once you’ve confirmed your legitimate mail passes.
The step that trips people up is the inventory. Almost every business sends email from more places than they realize. The mail server is obvious. The CRM, the invoicing platform, the scheduling tool, and the old form on the website get forgotten, and each one has to be authenticated before you tighten the policy.
If you want to work through it yourself, our step-by-step guide to email deliverability walks through the fixes. If you’d rather hand it off, this is standard work inside managed IT services in Louisville, including reading the DMARC reports each month so the policy tightens on evidence instead of guesswork.
Your Domain Is Part of Your Reputation
Three things to take away. The From line proves nothing on its own, so anyone can put your name on a message today. A DMARC record at p=none protects nobody. And the fix is a staged rollout, not a switch you flip on a Friday afternoon.
The whole project usually takes a few weeks of monitoring and a handful of DNS changes. Compared to a client wiring money to a stranger who used your name, that’s a bargain.
Run the scan first and see where you stand. If the result raises questions, schedule an intro call and we’ll walk through what it means for your domain.
Frequently Asked Questions
What is email spoofing?
Email spoofing is when someone sends a message with your domain in the From address so it looks like it came from your company. It’s used to trick clients, suppliers, or staff into paying fake invoices, changing banking details, or handing over information. Your systems don’t have to be compromised for it to work.
What are SPF, DKIM, and DMARC in simple terms?
SPF is a list of servers allowed to send email for your domain. DKIM is a signature proving a message came from you and wasn’t altered along the way. DMARC ties the two together, tells receiving servers what to do with messages that fail, and reports back on who is sending email as your domain.
Does DMARC stop all email impersonation?
No. DMARC stops someone forging your exact domain. It does not stop lookalike domains such as yourcompany-invoices.com, and it does not stop display-name spoofing, where the sender’s name says your company but the address behind it is different. Those still need staff awareness and payment verification habits.
Will setting up DMARC block my own emails?
Not if you roll it out gradually. Starting at p=none lets you watch the reports and confirm your legitimate mail passes before you move to quarantine and then reject. Jumping straight to reject without checking first is what causes legitimate email to disappear.
Do I need these records if I don’t send many emails?
Yes. They protect your domain from being spoofed no matter how much email you send, and they help your messages reach the inbox. Google, Yahoo, and Microsoft all expect proper authentication now, and mail without it is more likely to get filtered.
Find Out Where Your Domain Stands
Most business owners have never checked whether their domain can be spoofed, and the answer takes a minute to get. Run our free email deliverability scanner, then get in touch if you want help reading the results or moving your policy from monitoring to real protection.
