Suped

How can spammers send emails from real addresses, and is this a DMARC configuration issue?

Summary

Spammers can, and often do, send emails that appear to originate from real or legitimate addresses, a practice known as email spoofing. The challenge isn't in preventing them from attempting to send such emails, as the 'From' field is easily manipulated. Instead, the real hurdle for spammers is ensuring these spoofed emails are successfully delivered to recipients' inboxes, rather than being flagged as spam or rejected outright. This is where robust email authentication protocols like SPF, DKIM, and DMARC become critically important.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers widely acknowledge that email spoofing was a prevalent and relatively easy tactic before the widespread adoption of modern email authentication protocols. They emphasize that while it's still technically possible for anyone to forge a 'From' address, the true hurdle for spammers is getting those messages successfully delivered. The consensus is that strong authentication, particularly DMARC with a strict policy, is the most effective defense against unauthorized use of a domain.

Marketer view

An email marketer from Email Geeks indicates that anyone can send emails from any address; this is known as spoofing. The real challenge, however, lies in properly delivering these emails to the recipient's inbox, which is where authentication becomes crucial.

16 Feb 2023 - Email Geeks

Marketer view

A marketer from Email Geeks explains that prior to SPF, DKIM, and DMARC, email spoofing was incredibly easy because the 'From' domain is simply a field that any sender could populate. These modern protocols now make it much harder.

16 Feb 2023 - Email Geeks

What the experts say

Deliverability experts agree that email authentication protocols are the frontline defense against spoofing. They emphasize that while sending an email with a forged 'From' address is simple, it's the strict enforcement of policies like DMARC that determines whether that email ever reaches its intended recipient. Experts often highlight the importance of not just implementing, but also carefully configuring and monitoring DMARC to ensure it aligns with legitimate sending practices and actively combats malicious attempts to impersonate a domain.

Expert view

A deliverability expert from Email Geeks explains that the core purpose of DMARC is to define how receiving mail servers should treat emails that claim to be from your domain but fail SPF or DKIM authentication.

10 Mar 2023 - Email Geeks

Expert view

A deliverability expert from Spamresource highlights that while spammers can easily forge the visible 'From' address, DMARC allows domain owners to publish a policy that explicitly tells receivers to quarantine or reject unauthenticated mail from that domain.

15 Jan 2024 - Spamresource

What the documentation says

Official documentation and technical guides consistently explain that email spoofing is a fundamental vulnerability in the original email architecture that authentication protocols like DMARC, SPF, and DKIM were developed to address. They clarify that while it’s easy for spammers to manipulate the visible 'From' address, these protocols provide a framework for receiving mail servers to verify the legitimacy of the sending domain. The documentation underscores that proper DMARC configuration, especially with stricter policies, is vital for protecting domains from impersonation and improving email deliverability.

Technical article

WP Mail SMTP's documentation emphasizes that a DMARC record enables an email server to distinguish legitimate emails from spam messages that attempt to use your domain, thereby safeguarding your brand and recipients.

22 Mar 2023 - WP Mail SMTP

Technical article

Hornetsecurity's blog on DMARC clarifies that emails failing SPF or DKIM checks and configured with a DMARC policy set to quarantine will be marked as spam, effectively reducing the impact of fake invoices or impersonations.

10 Apr 2023 - Hornetsecurity

12 resources

Start improving your email deliverability today

Get started