The email spoof simulator sends a controlled email using a sender name and address you specify. Use it with clients and prospects to demonstrate the risk of leaving a domain without an enforced DMARC policy.
Before you start
- You must have authorization from the sender domain owner.
- The recipient must agree to receive a spoof test email.
- Use a sender domain with no DMARC record or a
p=nonepolicy. The simulator stops the test if it finds an enforcedp=quarantineorp=rejectpolicy.
You can check the sender domain's current policy with the DMARC checker.
Run a spoof test
- Select your MSP workspace, then go to Tools > Email spoof simulator in the Test section.
- Enter the Sender email address and Sender name you have permission to use.
- Enter the consenting recipient's address in Receiver email address.
- Turn on both switches to confirm the sender's authorization and recipient's permission.
- Click Send email, then ask the recipient to check their inbox, junk folder, and quarantine.

Email spoof simulator with example sender and recipient details, authorization switches, and the Send email button
What the email looks like
The email uses the subject Quick confidential request and your chosen sender identity. Its sample message demonstrates a gift card request, with a prominent security demonstration banner telling the recipient not to pay, reply, download, or take any action. Suped generates the message content automatically.

Example spoof email in an illustrative Outlook reading pane, showing the sender identity, security demonstration banner, and sample message
Understand the result
- Email sent. The sending service accepted the test. Confirm where it arrived with the recipient; this message does not confirm inbox placement.
- Email was rejected. The sending service could not complete the test. This result alone does not confirm that DMARC blocked it.
- Enforced DMARC policy. The simulator found a quarantine or reject policy and did not send the email.
A single test shows what happened to that message. Use DMARC monitoring to review a client's authentication results and plan their move to an enforced policy.