How to Stop Email Spoofing, From Someone Who Just Got Impersonated

Person lying in the grass wearing fake glasses, bushy eyebrows, and a mustache with a GruffyGoat t-shirt

By Nathan Duvall

Published

An email I didn’t send

Last week, several of our clients got an email from me. It had our logo, my name and title, and a warning that their website had missed a required WordPress update and had to be fixed by a deadline. While they were at it, it suggested this would be a good time for a full SEO setup.

The problem is, I didn’t send it.

The impersonation email, sent from nathan.guffygoat@gmail.com with the GruffyGoat logo and Nathan's name in the signature. Client details hidden.
The email as our client received it, with their details hidden.

One client noticed it came from a Gmail address with gruffy misspelled, and asked us before replying. It was a scam, and nobody lost anything.

Unfortunately, this kind of thing keeps getting easier to pull off. The same popular AI tools that everyone’s using also let scammers write a convincing email in someone else’s voice in seconds and send it to as many inboxes as they want. A misspelled address was the only giveaway on ours. The next one might not have one at all.

It sent me straight to our own email DNS records, which is what the rest of this post is about!

What we could and couldn’t have done about it

Email spoofing is sending a message that looks like it came from someone it didn’t come from. Nothing we could have set up would have stopped that email. The sender used a free Gmail account and information anyone can find on our website. As far as Gmail could tell, it was a normal message from a normal Gmail user.

That’s email impersonation. Sometimes it’s display-name spoofing like ours: a real name on top of an unrelated address. Sometimes it’s a lookalike domain, 1 letter off from the real thing, or one that’s even harder to detect if you don’t know the real domain. Unfortunately, your own settings can’t block these either, because the sender never touches your domain.

Domain spoofing is different. That’s someone forging your actual address, so the email looks like it came from you@yourcompany.com. That’s how most fake invoice scams work. It’s the more dangerous of the two, because it passes the glance test that caught ours. And fortunately, domain spoofing can be blocked.

How to tell if an email is spoofed

You can check for email spoofing in 2 passes:

First, read the actual address, not the name. Hover over or tap the sender. A business writing from a free Gmail, Outlook, or Yahoo account deserves a second look, and so does a company name that’s off by a letter or alerts your spidey-senses in other ways. Then read the email like a skeptic. A surprise deadline and a sales pitch in the same message is the pattern nearly all of these follow.

Second, look at what the mail servers saw. In Gmail, open the message, click the 3 dots, and choose Show original. In Outlook, look for the message headers under message details. Near the top, you’ll see SPF, DKIM, and DMARC, each marked pass or fail. If an email claims to come from a company’s own domain and DMARC fails, it was forged.

How to stop email spoofing on your own domain

3 records in your domain’s DNS do the work. If you’re thinking about email security for a small business and only have time for one thing, make it this. Gmail and Yahoo already require these records from anyone sending email in bulk, and the rest of us are better off having them too.

Picture an office building with a front desk. SPF is the list of who’s allowed in, meaning every service that sends email as your company. DKIM is a seal on each letter that proves it came from your email provider and wasn’t changed along the way. DMARC tells the front desk what to do with anyone who fails.

DMARC is 1 line of text, and the setting that matters is the policy:

v=DMARC1; p=reject; sp=reject; rua=mailto:reports@yourdomain.com

At p=none, failing mail still gets delivered. At p=quarantine, it goes to spam. At p=reject, it’s refused and never arrives. Reject is the goal. The sp setting does the same for subdomains, and rua is where reports get sent so you can see who’s sending as you.

If you’re starting from nothing, publish SPF and turn on DKIM for every service that sends as you, then publish DMARC at p=none with reporting on. Google’s own DMARC setup guide walks through it if you’re on Google Workspace. Give it a few weeks, fix anything the reports show failing, and move to quarantine and then reject.

What we changed on our own domain

Our DMARC was already at quarantine, so forged gruffygoat.com mail was going to spam. We turned on reporting through Cloudflare’s free DMARC Management, set subdomains to reject, and upgraded our Google Workspace DKIM key from 1024-bit to the 2048-bit Google recommends. Once the reports confirm everything legitimate is passing in a week or so, we’ll move to reject.

If you’re upgrading Google Workspace DKIM yourself, give the new key a new selector name instead of reusing “google.” The old key keeps working until Google switches over, so your mail never fails in between.

While none of this would have stopped last week’s email, it will stop the worst version of it.

How to check your own records

This takes about 5 minutes. Google’s free Admin Toolbox and MXToolbox both look up SPF, DKIM, and DMARC for any domain. Type in yours. A missing DMARC record, p=none, or sp=none are the results worth acting on.

Then send an email from your work address to a personal Gmail account and open Show original. 3 passes mean your mail is authenticated. If what comes back reads like a foreign language, send it to us, and we’ll help you translate it.

If someone is impersonating you

When someone is spoofing your email from an address that isn’t yours, your DNS records won’t help. Report the account instead. For a Gmail address, use Google’s abuse report form. If it landed in your Gmail inbox, you can also open it, click the 3 dots, and choose Report phishing. Then give your clients a heads-up like we just did, so they know what your real email looks like, and don’t reply to the scammer.

Common questions

Can email spoofing be stopped?

You can stop forgery of your actual domain almost entirely. A DMARC policy of reject, backed by SPF and DKIM, tells Gmail, Outlook, and nearly every other provider to refuse mail falsely claiming to be from you. You can’t block impersonation from a different address with anything you publish. Reporting the account and warning your clients is the defense there.

Do I need DMARC?

If you send email from your own domain, yes. It’s free, it’s 1 DNS record, and Gmail and Yahoo already expect it from anyone sending in bulk. Even a p=none record with reporting turned on shows you who’s sending as you.

Should I be worried if my email is spoofed?

It’s worth acting on, though it usually doesn’t mean you’ve been hacked, so don’t freak out. Check your DMARC policy and let your clients know. If messages you didn’t write show up in your Sent folder, that’s a compromised account, so change your password and turn on two-step verification immediately.

How can I tell if my email has been spoofed?

Usually someone tells you, like our clients did. Bounce notices for messages you never sent are another sign. DMARC reports show any server trying to send as your domain, which is another reason to turn reporting on before you need it.

Why did I get an email from my own email address?

Someone forged your address, and your domain isn’t telling mail servers to refuse it. These are usually scary-sounding emails demanding payment. Moving your DMARC policy to quarantine or reject stops most of them.

What’s the difference between DMARC quarantine and reject?

Quarantine sends failing mail to spam, where it can still be opened. Reject refuses it, so it never arrives. Quarantine is a sensible place to sit while you confirm your own mail passes. Reject is where you want to end up.

Let us check your domain

Most businesses we talk to have never even heard of these acronyms, much less looked at their DNS records to see if they’re configured correctly. None of this is a new problem, but these types of issues are worse than ever, thanks to AI making a spammer’s life a lot easier.

If I’ve lost you in my explanation of all of this, don’t sweat it! We care about these kinds of annoying, nitty-gritty, in-the-weeds issues. It’s the part of running a website most people never see, and it’s a big part of what we do through our Partnership Plan. Send us your domain, and we’ll look up your SPF, DKIM, and DMARC records and tell you in plain English what we’d change, if anything. No charge.

Check my domain

If you’re already a GruffyGoat client, this is part of your ongoing website support. Reach out to our support team, and we’ll get you squared away. It’s also one of the checks in a website security audit, if you’d like the rest of your setup looked at, too.

And if an email ever shows up with my name on it and news from a WordPress conference meeting, ask us before you reply. Spoiler alert: I’m not much of a WordPress conference guy. #nerds 😉

Ready to Start
Your Project?

CTA Blob
CTA Blob
CTA Blob
CTA Blob
CTA Blob