15–25 min Updated

Email Spoofing

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Email spoofing is the sending of email messages with a forged "from" address.

Prevalence
Common
Exploitability
Easy
Impact
Worrying

What is email spoofing?

Email spoofing is an impersonation attack in which an attacker sends email with a forged "from" address, making the message appear to come from a trusted sender such as your organization. It works because SMTP does not authenticate senders by default, and it is used for phishing and fraud. SPF, DKIM and DMARC let receivers detect forgeries.

What you'll learn

  • Why SMTP lets anyone forge the sender of an email
  • How spoofed email drives phishing attacks on your users
  • How SPF and DKIM let mail providers detect forged messages
  • Email Spoofing lab

    Watch a phishing email with a forged sender lead a user to a fake password reset page that saves their credentials. Then see how SPF and DKIM let mail providers flag forged mail, and edit an email yourself to watch its DKIM signature change.

  • How to prevent Email Spoofing

    The prevention guide covers two approaches:

    • Implement the Sender Policy Framework (SPF)
    • Implement DomainKeys Identified Mail (DKIM)
  • Email Spoofing quiz

    Two questions. Passing marks the lesson complete.

  • Open Redirects

    Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.

  • DNS Poisoning

    If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.

  • Subdomain Squatting

    Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.

  • Host Header Poisoning

    It's dangerous to rely on the value supplied in the Host header of an HTTP request.