Cold email glossary

Email spoofing

Email spoofing is forging the From address of an email so it appears to come from a domain the sender does not control. SPF, DKIM, and DMARC are the authentication standards built to detect and block it.

What is email spoofing?

Spoofing is possible because SMTP, the protocol that moves email, was designed in an era of implicit trust. Nothing in the protocol verifies that the address in the From header matches the server that actually sent the message, so any server can claim to be anyone. Attackers exploit this for phishing, invoice fraud, and business email compromise, sending mail that appears to come from a bank, a vendor, or your own CEO.

Three standards were created to close the gap. SPF lets a domain publish which servers are allowed to send on its behalf. DKIM adds a cryptographic signature proving a message was authorized by the domain and was not altered in transit. DMARC ties both checks to the From address people actually see, tells receiving servers what to do when the checks fail (nothing, quarantine, or reject), and sends the domain owner reports about who is sending as them.

The same checks that catch forgeries now grade legitimate senders. To a mailbox provider, unauthenticated mail is indistinguishable from spoofed mail, so it gets treated with suspicion regardless of intent. Google and Yahoo's published bulk sender requirements made SPF, DKIM, and DMARC mandatory for high-volume senders, turning anti-spoofing infrastructure into a baseline deliverability requirement.

Why it matters in cold email

For cold email, authentication is the entry fee. A broken SPF record or a missing DKIM signature does not just weaken a trust signal, it makes your legitimate outreach look like the attack the system was built to stop, and filters respond accordingly. Separately, publishing an enforcing DMARC policy on your primary company domain protects your brand itself: without one, anyone can send mail as you, and your customers and prospects may receive it.

How Sendful handles it

Every dedicated sending domain Sendful builds is configured with SPF, DKIM, and DMARC before the first message goes out, and Sendful never sends from your primary domain. Outreach runs on infrastructure that authenticates cleanly while your company's own mail stays untouched.

FAQ

Email spoofing questions

Can't find what you're looking for? Get in touch.

How do I stop someone from spoofing my domain?

Publish SPF and DKIM, then add a DMARC record and move its policy from none to quarantine or reject once the reports show your legitimate mail passing. At a policy of none, receivers take no action against forgeries, so enforcement is the step that actually blocks spoofed mail.

Is email spoofing illegal?

Using a forged sender identity for fraud or phishing is a crime in most jurisdictions, and in the US, CAN-SPAM prohibits false or misleading header information in commercial email regardless of intent. Legitimate cold email always sends from a domain you actually control. This is general information, not legal advice.

How can I tell if my own email is authenticated?

Send a message to a Gmail account, open it, choose Show original, and check that SPF, DKIM, and DMARC all read pass in the Authentication-Results summary. Free header analyzer tools do the same job for any provider.

Book a call

Done reading? We run all of this for you.

Book a call and leave with a custom outbound plan, your ICP, opening sequences, and a deliverability check, whether or not we work together.