How email spoofing and forgery actually work
Email was designed in an era of trust, and the protocol lets a sender simply type whatever address they want in the From line — much like writing any name you like as the return address on an envelope. That is spoofing, and it is the single most common trick behind malicious mail.
Common techniques we identify:
- From-address spoofing — the visible sender is faked to look like a bank, colleague or the victim themselves.
- Display-name spoofing — the real address is obscure, but the friendly name shown reads as a trusted person or brand.
- Look-alike domains — a near-identical domain (swapped or added letters) that passes a quick glance.
- Forged Received lines — fake routing hops added to disguise the true origin.
- Reply-To redirection — the reply quietly goes to an attacker-controlled address, not the one shown.
Spoofing leaves fingerprints. Authentication failures, inconsistent headers and mismatched routing all expose the deception, and the report sets out exactly which techniques were used against you.

0 comments
Sign in with your TDesk account to comment.