Email Management: Email Spoofing
Spammers will often forge email headers in an attempt to trick users into the opening or even responding to what appears to be a legitimate email. The email header may seem to have originated from a friend, business acquaintance, or product or service that a user may have. This tactic is often used in spam and phishing campaigns, and although it is mostly a nuisance, there can be malicious forms also.
What is email spoofing?
One should NEVER respond to any email that is asking the user for sensitive data or information like passwords, credit card, or social security numbers. NEVER, EVER click a link in a suspicious email! Legitimate companies will not request their customers to submit private data via email.
How can you tell if your email address was used in a spoofing campaign?Your inbox may all of a sudden get flooded by bounce messages listing a variety of reasons why the messages are getting bounced. This typically does NOT mean that your personal computer has been hacked. If you are concerned, you should immediately change your email account password to be safe.
If you have access to your email header you can often spot issues. In the example below
- the addresses From: and Reply-To: are different
- You may think you are writing to email@example.com
- but in reality, your response is going to firstname.lastname@example.org.
mail from: email@example.com rcpt to: firstname.lastname@example.org data From: YourBoss <email@example.com> Subject: Raise! Date: February 13, 2019 3:30:58 PM EDT To: user1 <firstname.lastname@example.org> Reply-To: YourBoss <email@example.com> Hi User1 Please reply back to this message for details on your raise. Regards, YourBoss
How can I avoid becoming a spoofing victim?
- Keep your antivirus software updated.
- Add a TXT/SPF Record to your DNS.
- Never respond to or click a link in a suspicious email.
- If you are in doubt about the authenticity of an email, contact the friend or business for verification separately.
- Change your email password frequently.
Until stronger email protocols are in place, this will continue to be an issue. Other options may be to purchase more secure email offerings like Microsoft 365 or Google Workspace.