Stop Email Spoofing & Website Spoofing: Best Tips

What is Email Spoofing

30 June 2017

What is Email Spoofing?

Email spoofing has existed since the inception of the SMTP (email) protocol. Emails were designed to be open and accessible and weren’t particularly secure. It’s trivial for attackers to craft emails with forged headers using simple tools like telnet. These generated or spoofed emails can appear to come from anyone in the world. To help you find the right solution, Server Consultancy has identified some of the best email security solutions.

Cybercriminals consistently take advantage of how simple it is to impersonate a business website or email. You need complete visibility into who misrepresents your brand online if you want to stop email spoofing attacks. Simply defending your property is insufficient today. To protect the reputation you have worked so hard to build, it’s time to switch from defence to offence.

Attackers need to find an open mail relay to send forged emails. These email servers accept and send an email on behalf of anyone. Competent email administrators realise the dangers of open relays and disable the functionality. Unfortunately, available mail relays still exist, and attackers still use them to send emails that appear to come from someone else.

email spoofing

How to Protect Against Email Spoofing

While there is nothing anyone can do to prevent attackers from exploiting the open SMTP standards with available mail relays, there are ways you can help identify and block this type of spoofed email. The Sender Policy Framework (SPF) is a standard that allows email servers to validate that email from a specific domain comes from that domain’s email servers. For instance, if an email has a sender address of employee@serverconsultancy.co.uk, your email server can use SPF to validate the proper email servers for “serverconsultancy.co.uk” If that email came from another server, like an open mail relay, your server would block it as spoofed.

Server Consultancy does have an SPF record for our domains. If your email gateway supports SPF (most do), we recommend you configure it to use SPF to block these sorts of emails. Here’s a quick primer for using SPF with Microsoft Exchange Online.

Email spoofing is only possible because some email servers still act as open mail relays on the Internet. Many of these are malicious servers which email security products blocklist. However, sometimes new administrators still mistakenly misconfigure their email servers as well. You can leverage WatchGuard’s Firebox to prevent your customers’ email servers from relaying email, thus helping protect the Internet from spoofed email.

To summarise, trust your instincts if you receive a strange email message. It is likely a spoofed email. You should:

  • Delete the message and avoid interacting with it
  • Do not click any links or attachments it may contain (always navigate to sites directly)
  • Enable SPF checks for trusted domains on your email gateway to detect and block spoofed emails in the future.

Email Spoofing involves The sender address being automatically input when a user sends a new email message using a standard email client (like Microsoft Outlook). However, an attacker can send messages programmatically by configuring the sender address to the desired email address and using simple scripts in any language. Email API endpoints let senders define their addresses regardless of whether the address is valid. Additionally, outbound email servers are unable to validate the sender address.

Using the SMTP (Simple Mail Transfer Protocol), outgoing email is retrieved and forwarded (SMTP). The message is first transmitted to the outgoing SMTP server set up in the client software when a user hits “Send” on an email client. The receiving domain is recognised by the SMTP server, which directs the message to the domain’s

Do you have questions about email spoofing or looking for a defender for your office 365 email infrastructure? Contact the Email Support Company in London for help.

Related Links