How SPF, DKIM and DMARC stop email spoofing vs phishing

Email authentication title card covering SPF, DKIM and DMARC

Article by

PC Scientist

PC Scientist is a professional IT support provider helping homeowners and small businesses across New South Wales. We specialise in computer repair, business IT support, networking, Wi-Fi optimisation, cybersecurity, email support, device setup and security camera solutions.

Our articles are written using practical, real-world experience to help Australians solve technology problems with clear, accurate and easy-to-follow advice. When an issue requires professional assistance, we're here to help with onsite and remote support.

That email looks like your bank. Or your boss. Your stomach drops before you have even opened it. Spoofing is the fake name on the envelope. Phishing is the scam inside. If it wants money, a password, or "act now", stop. Do not click. Check through a number or site you already trust.

  • Ask whether the name matches the address. Tap the sender. "IT Support" with a random Gmail underneath is the tell.
  • Ask what they want. A payment change, a login, or a file to open. Real suppliers rarely dump that on you at 4:50 on a Friday.
  • Ask whether you can check another way. The number on last month's invoice. The number on the back of the card. Not the one in the email.
  • Ask whether your own domain is even locked. Missing SPF or DMARC is how someone sends mail that looks like it came from you.

If you would rather not guess the headers, Cybersecurity Scientist can look with you. Sydney inboxes can start with cybersecurity help across Sydney. Central Coast homes can use cybersecurity help on the Central Coast.

Want pictures of the usual bait first? Stay with phishing email examples. If the mailbox is already taken, skip ahead to recover hacked email.

Key takeaways

Spoofing fakes the sender. Phishing is the scam riding on that fake. Check the real address before you click. SPF, DKIM and DMARC stop most people from sending as your domain. They do not stop a lookalike domain or a mailbox that is already compromised.

Point Details
Two different jobs Spoofing is the disguise. Phishing is the ask for money, a password, or a file.
SMTP is trusting The From line you see can be typed in. That is why a fake can look tidy.
Check before you click Real address, Reply-To, hover the link, then call a number you already have.
SPF, DKIM, DMARC They tell other mail servers who may send as you. Roll DMARC out in stages so real mail does not bounce.
What they cannot catch A lookalike domain, a hacked genuine account, or a QR code that hides the URL.

Spoofing vs phishing

Spoofing forges the sender so the message looks like it came from someone it did not. Phishing is the social engineering that tries to steal a login, drop malware, or move money. Proofpoint treats spoofing as the disguise that makes phishing feel believable. One is the costume. The other is the con.

A few labels keep turning up. They are not interchangeable.

  • Spear phishing uses a real detail about you. Your workplace. A recent order. A colleague's name.
  • Business email compromise impersonates a boss or a supplier, then asks you to change bank details.
  • Domain impersonation registers a lookalike, like a swapped letter or an extra hyphen, then wraps it in a familiar display name.

Spoofing can exist without phishing. A test against a mail server is the boring example. Almost every serious phishing campaign still uses some form of spoofing to get past that first glance. Cloudflare's spoofing explainer is the clean technical version if you want the plumbing.

How email spoofing actually works

Email was built to be delivered, not to prove who sent it. SMTP largely trusts what the sending server claims. The name and address you see can be typed in with almost no check.

There are two From fields. The gap between them is where a lot of spoofing hides.

  • Envelope-from is used behind the scenes for delivery and bounces.
  • Message-from is what sits in your inbox.

Cyber.gov.au notes that attackers exploit that difference. That is why DMARC checks alignment instead of trusting either field alone. If they do not match, and nobody is enforcing the check, a forged message sails through.

Phishing then does the payday. A fake login page. An attachment with malware. Or a polite request that you reply with the details yourself. The polish, the urgency, the "invoice attached" subject, that is phishing's job. Spoofing just got it past the door.

One messy bit. Mailing lists and forwarding can break authentication even for genuine senders. ARC exists to carry the original result through those hops. A failed check is not always a scam. A passed check is not always safe. Your job as the reader does not change. Pause. Verify.

Overview diagram of how email spoofing actually works

What the attacks look like

Three patterns cover most of what lands in a normal inbox.

  1. Spear phishing with a personal detail. Your employer. A purchase. A colleague. Then a fake invoice or a password reset.
  2. Business email compromise. A CEO, a bookkeeper, or a regular supplier. Often a lookalike domain. Then a bank transfer or a quiet change to payment details.
  3. Lookalike domains and display-name tricks. micros0ft.com. An extra hyphen. Or the name "IT Support" with an unrelated address underneath. Proofpoint's research keeps coming back to the same point. Most people never check the address behind the name.

A typical Friday looks like this. The attacker spoofs a supplier. The email cites a real invoice number. It lands at 4:40 when everyone wants it gone. Accurate detail plus manufactured hurry is why BEC still costs small businesses real money.

How to tell if an email is spoofed

Run these before you do anything else with a message that feels off.

  • Check the real sender address, not the display name. A mismatch is one of the clearest tells.
  • Look at Reply-To. Some fakes show a legit name, then quietly route your reply somewhere else.
  • View the full headers if your mail app lets you. That shows the sending server.
  • Hover the links. A short URL, or a domain that is almost right, is a warning.
  • Watch for hurry, surprise attachments, generic greetings, and money. eSafety frames phishing as a trust problem. The fix is a pause, not a faster click.

Pro Tip: Screenshot the email and copy the headers before you delete it. If you later talk to the bank, eSafety, or us, that evidence saves a long reconstruction.

Then verify through a channel you already trust. Last month's invoice. The number on the card. Nothing supplied in the email itself.

How to keep more of them out

Habits do more than another toolbar. The software still matters.

  • Turn on multi-factor authentication everywhere it is offered. A stolen password is then not the whole account.
  • Use a unique password per account, ideally in a password manager.
  • Keep Windows, the browser, and the mail app updated. A lot of payloads still ride old holes.
  • Build a verification habit. Money or account access means a call on a number you already have.
  • Do not reply to a suspicious message, even to ask "is this real?" A reply confirms the address is live.
  • Report it. Forward it to the organisation being impersonated. Use eSafety for scams. Call the bank if money was involved.

The people who get caught are rarely careless. They are moving fast on a Friday. That is when these emails get sent.

Newcastle and Hunter inboxes that want the domain records checked, not guessed, can start from cybersecurity help in Newcastle.

SPF, DKIM and DMARC

You can spot one fake at a time. A business needs something that works at scale. That is this trio.

  • SPF lists which mail servers may send as your domain.
  • DKIM signs the message so the receiving server can tell if it was altered in transit.
  • DMARC checks that the visible From lines up with what SPF and DKIM actually verified.

Together they close most of the gap SMTP left open.

SPF, DKIM and DMARC email authentication flow

Rolling DMARC out in one hit can bounce your own mail. Cyber.gov.au recommends stages. Start at p=none and watch the reports. Move to p=quarantine when you trust who is sending. Finish at p=reject when you are sure. The reports are the part most businesses skip. They show who is sending as you before you lock the door.

These three do not catch a lookalike domain. That is a different domain, technically legitimate, just deceptive. They also cannot stop an attacker who already has a real mailbox. Filtering and a verification habit still have to cover that gap.

If Microsoft 365 is in the mix, a clean mail flow still needs the right send path. That sits in scan to email 365 when a printer is the weak link, or migrate email to 365 when the whole tenant is moving.

If you already clicked

Move, but in this order.

  1. Stop. Close the tab. Do not type anything else. Do not click around trying to undo it.
  2. Change passwords from a different, trusted device. Email and banking first. Turn on MFA if it is off.
  3. Scan the device. If it feels infected, unplug it from the network so nothing spreads.
  4. Call the bank if money or card details were involved.
  5. Keep the original email and a screenshot before you report it.
  6. Get a person to look if you are not sure what was touched. Guessing on a shared or business PC is how a bad afternoon becomes a bad month.

Reading the email is rarely the harm. The click is. If the mailbox is already someone else's, go to recover hacked email and lock it before you tidy anything else.

Newer bait is getting harder to spot. AI has cleaned up the grammar. Some BEC jobs now follow the email with a phone call that sounds like the boss. QR codes hide the URL, so the old "hover the link" habit does not help. The technical defences above still work. They work better with a slow "does this make sense?" before you act.

PC Scientist can lock this down with you

When someone calls after a scare, the order matters more than speed. Contain first. Isolate the account or the device. Then remove what got in. Then restore access. Then harden mail flow so the same trick does not work twice. Jumping straight to "fix it" without containing it is how it spreads.

Most of the work is unglamorous. Forced password resets. A proper SPF, DKIM and DMARC review. Malware removal if a device was touched. Cybersecurity Scientist can do that remotely if screenshots of the headers are enough, or onsite if the PC itself needs a look.

Tell us whether you clicked, whether money moved, and whether the domain is yours to lock. We will say what to do in the next hour, and what can wait. Call 0493 563 381, or pick your area below.

PC Scientist

Sources

These pages help when you want a second, independent walk-through:

Help centre

Frequently Asked Questions

Straight answers about email spoofing vs phishing - without jargon or pressure. Call 0493 563 381 for advice, or get help below.

Want the quickest answer? 0493 563 381 for free advice.

It is a forged From line. The display name, the address, or both, are faked so the message looks like it came from someone you already trust.

The usual four are forged email headers, a lookalike domain, a fake display name, and caller ID spoofing on the phone. Email scams often stack the first three together.

Tap the sender. Check the real address, not just the name. Look at Reply-To. Hover every link. If money or a password is involved, call a number you already have, not the one in the email.

Reading it is usually fine. The harm starts when you click a link, open an attachment, or type a password on the page it sends you to.

They are not the same job. Spoofing is the disguise. Phishing is the scam. The damage comes from the phishing step: stolen logins, malware, or a payment that went to the wrong account.

Cybersecurity across NSW

If you clicked a link, or SPF and DMARC on your domain still look messy, that is okay. Get help in your area and we will take it from here.

Cybersecurity statewide

Start here

Get cybersecurity help

Optional Need a Sydney city or region?

Choose a side of Sydney

These are Sydney cities and regions, such as the Northern Beaches or Inner West. First tap a side of Sydney. Then open the city or region that covers you.

C Sydney City / Inner 3 areas
N Northern Sydney 6 areas
NW North-West / Central Sydney 3 areas
W Western Sydney 1 area
SW South-West Sydney 3 areas
S Southern Sydney 2 areas
Optional Find your suburb

Type a suburb from our listed coverage. This opens the matching city or region page for this topic. Listed suburb pages are general technology services, not this specialist page.

If your suburb is not listed, use the city or region list above, or call 0493 563 381.

    Need help with your setup? Call or text PC Scientist on 0493 563 381 for initial advice, request a callback at a suitable time, get a quote or book online to receive the advertised online-booking discount where applicable.

    Disclaimer

    The information in this article is provided for general educational and informational purposes only. While PC Scientist strives to keep all content accurate and up to date, technology issues can vary depending on your device, software, network configuration, and individual circumstances. Always back up important data before attempting repairs or system changes. If you are unsure or the issue cannot be resolved safely, contact PC Scientist today for professional onsite or remote IT support. PC Scientist is not liable for any loss of data, damage, or other issues resulting from the use of the information provided in this article.

    shape
    shape
    Need help now? Not sure what to click or what to do next?

    Talk to PC Scientist for free advice, calm and practical IT help