Most people have encountered an email that appeared to come from someone else. More than 90% of cyberattacks begin with an email or another form of communication aimed at people in private life, business and public institutions. This article explains what spoofing is, how email and domain spoofing work and how to reduce the risk.
Spoofing—what is it?
Spoofing is an attack in which a criminal pretends to be an institution, company, bank, public office or person that the recipient knows and trusts. The objective is usually to steal data or money.
Common types include:
- email spoofing;
- domain spoofing;
- caller-ID or phone spoofing;
- IP spoofing;
- DNS spoofing;
- application spoofing.
This article focuses on the first two types.
What is email spoofing?
Email spoofing is the impersonation of a sender in a message. It can support spam or phishing campaigns. The criminal wants the email to appear genuine and to persuade the recipient to click a link, open an infected file, transfer money or install an application.
To increase credibility, the attacker copies the company’s template, tone, logo and signature. The message may therefore be difficult to distinguish from legitimate correspondence unless the sender address, links and context are checked carefully.
Domain spoofing
In domain spoofing, the criminal creates a domain or address that resembles a trusted one. A single changed character, an additional word or a different top-level domain may be enough to mislead the recipient. The same manipulation can be used to impersonate a supplier, bank or internal department.
How to protect yourself against spoofing
Attacks targeting people are increasing because criminals know that human attention is a key security boundary. Everyone is susceptible to social engineering, so awareness should include employees, family members and colleagues.
Remember to protect yourself and your company
- check the sender’s complete domain, not only the display name;
- verify the landing page before entering credentials or other data;
- type important addresses manually instead of following an unexpected link;
- use unique passwords and enable multi-factor authentication;
- treat spelling errors, unexpected prizes, inheritances and urgent requests as warning signs;
- keep software and browsers up to date;
- use email and DNS security controls where appropriate.
Regular training and practical phishing simulations help people recognize spoofed messages and develop safer habits.

