Email spoofing is fake email that uses your domain in the From address. SPF, DKIM, DMARC, RUA reports and SPF flattening are how you make that harder, without moving your website.
Email spoofing is fake email that uses your domain in the From address. SPF, DKIM, DMARC, RUA reports and SPF flattening are how you make that harder, without moving your website.
What email spoofing and fake email mean
Anyone can type your domain into the From header of an email. The mailbox that receives it often shows that address as if you sent the message. That is email spoofing. People also call it fake email, forged mail, or domain spoofing.
The message might ask finance to pay a changed invoice, or staff to open a link. The technical gap is simple: classic email did not prove that the visible sender owns the domain. SPF, DKIM and DMARC exist to close that gap for your exact domain.
What this is not
Lookalike domains. An address on a similar name (a swapped letter, an extra word) is not spoofing of your domain. DMARC does not stop it. Higher MailControl tiers can watch for similar names. That is a separate control.
Display-name tricks. A message can show your company name while the real address is somewhere else. Authentication checks the domain after the @ sign, not the display name.
A compromised mailbox. If an attacker sends from a real account you own, SPF and DKIM can pass. DMARC will not reject that mail. That is an account problem, not a missing DNS record.
Phishing in general. Phishing is the fraud. Spoofing is one way to make the fraud look like it came from you.
SPF: who may send for your domain
SPF is a DNS TXT record that lists the hosts allowed to send mail for your domain. Receivers check the sending server against that list. A simple fake email from a random server fails SPF when the record is present and evaluable.
SPF breaks when the record needs more than ten DNS lookups, or when you publish two SPF records. Legitimate mail can then fail authentication even though every vendor include looks correct. Read What is SPF? and the ten-lookup limit.
SPF flattening: when the sender list outgrows DNS
SPF flattening stores your authorised senders, resolves their includes on a schedule, and publishes a short target that stays under the lookup limit. It does not reject fake email by itself. It keeps SPF working so DMARC has a pass it can align to your From domain.
NovaMX MailControl offers SPF flattening on its own or inside MailControl bundles. Rates are on the Pricing page. The how-to is SPF flattening explained.
DKIM: the signature on the message
DKIM adds a cryptographic signature to selected headers and the body. Receivers fetch the public key from DNS (a selector, such as selector._domainkey.yourdomain) and check that the message was not altered.
A DKIM pass only helps against spoofing when the signing domain aligns with the visible From domain. A newsletter platform that signs with its own domain, while your brand sits in From, still looks like fake email to DMARC until you align it. Read What is DKIM?.
DMARC: the policy that asks receivers to act
DMARC ties SPF or DKIM to the From domain (alignment) and publishes what receivers should do when both fail. The record lives at _dmarc.yourdomain.
p=none monitors only. Receivers still deliver failing mail. This does not stop spoofing. It is where you start, so you can see legitimate senders before you block anyone.
p=quarantine asks receivers to treat failing mail as suspicious, often the spam folder.
p=reject asks receivers to refuse failing mail. This is the setting that actually reduces fake email from your exact domain.
Jumping to reject before every real sender passes alignment blocks invoices, tickets and newsletters you still need. Read What is DMARC? and the step-by-step setup.
DMARC RUA: who is sending as you
RUA is the report address inside the DMARC record (rua=mailto:...). Receivers send aggregate XML, usually once a day, listing which IP addresses used your domain and whether SPF and DKIM aligned. RUA does not block mail. Without it you are guessing which tools still send as you.
RUF is the optional forensic address. Most organisations start with RUA only. MailControl DMARC Reports hosts the RUA address and turns the XML into source lists. Read What is DMARC RUA? and DMARC Reports explained.
BIMI, MTA-STS and TLS-RPT
These sit next to authentication. They are not substitutes for it.
BIMI can show your logo in supporting inboxes. Strict DMARC is a usual prerequisite. See What is BIMI?.
MTA-STS asks other servers to use TLS when they deliver mail to you. It protects the transport path, not the From address. See What is MTA-STS?.
TLS-RPT is the report stream for TLS failures, separate from DMARC RUA.
How NovaMX MailControl helps
MailControl is the mail authentication module in My NovaMX. After you verify the domain you can order SPF flattening, DMARC reporting, a guided path from monitor to reject, BIMI and MTA-STS, or a bundle that combines them. The website can stay where it is. You publish DNS where the zone already lives, or let NovaMX DNS publish the records when we host the zone.
Start with the free mail check to see what the public internet already sees. Then read MailControl explained to choose Free, a single add-on, or a bundle. Current rates are on the Pricing page.
A practical order
Publish one SPF record that stays under ten lookups. Use SPF flattening if the include tree is already too deep.
Sign real outbound streams with DKIM and align the signing domain with From.
Publish DMARC at p=none with an RUA address you will actually read.
Fix every legitimate source that fails alignment.
Move to quarantine, then reject, when the reports are clean.
Common questions
What is email spoofing?
Email spoofing is forging the visible From address so a message looks like it came from a domain the sender does not control. Fake email is the everyday name for the same trick.
Does DMARC stop all fake email?
Enforced DMARC (quarantine or reject) tells receivers to distrust mail that fails SPF or DKIM alignment for your exact domain. It does not stop lookalike domains, display-name tricks, or mail sent from a compromised real mailbox.
What is DMARC RUA?
RUA is the address in your DMARC record that receives aggregate reports. Those reports show which systems sent mail using your domain. They do not block mail by themselves.
What is SPF flattening?
SPF flattening keeps your sender list under the ten DNS lookup limit so SPF still passes. It does not reject fake mail on its own. It keeps SPF usable so DMARC can rely on it.
E-mail spoofing is nepmail die uw domein in het From-adres zet. SPF, DKIM, DMARC, RUA-rapporten en SPF-flattening maken dat moeilijker, zonder uw website te verhuizen.
Wat e-mail spoofing en nepmail betekenen
Iedereen kan uw domein in de From-header van een e-mail zetten. De mailbox die het bericht ontvangt toont dat adres vaak alsof u het zelf verstuurde. Dat is e-mail spoofing. Mensen noemen het ook nepmail, valse e-mail of domein-spoofing. In het Engels heet het email spoofing of fake email.
Het bericht kan financiën vragen een factuur naar een ander rekeningnummer te betalen, of collega's vragen een link te openen. De technische opening is eenvoudig: klassieke e-mail bewees niet dat de zichtbare afzender het domein bezit. SPF, DKIM en DMARC dichten die opening voor uw exacte domein.
Wat dit niet is
Lookalike-domeinen. Een adres op een lijkende naam (een verwisselde letter, een extra woord) is geen spoofing van uw domein. DMARC stopt dat niet. Hogere MailControl-tiers kunnen op vergelijkbare namen letten. Dat is een aparte maatregel.
Weergavenaam. Een bericht kan uw bedrijfsnaam tonen terwijl het echte adres ergens anders staat. Authenticatie controleert het domein na het @-teken, niet de weergavenaam.
Een gekraakte mailbox. Verstuurt een aanvaller vanaf een echt account van u, dan kunnen SPF en DKIM slagen. DMARC weigert die mail niet. Dat is een accountprobleem, geen ontbrekend DNS-record.
Phishing in het algemeen. Phishing is de fraude. Spoofing is één manier om de fraude op u te laten lijken.
SPF: wie namens uw domein mag verzenden
SPF is een DNS-TXT-record met de hosts die mail voor uw domein mogen versturen. Ontvangers toetsen de verzendende server aan die lijst. Eenvoudige nepmail vanaf een willekeurige server faalt SPF wanneer het record aanwezig en controleerbaar is.
SPF breekt wanneer het record meer dan tien DNS-lookups nodig heeft, of wanneer u twee SPF-records publiceert. Legitieme mail kan dan authenticatie falen terwijl elke include er correct uitziet. Lees Wat is SPF? en de limiet van tien lookups.
SPF-flattening: wanneer de afzenderlijst te groot wordt
SPF-flattening bewaart uw geautoriseerde afzenders, lost hun includes op een schema op, en publiceert een kort doel dat onder de lookuplimiet blijft. Het weigert nepmail niet vanzelf. Het houdt SPF werkend zodat DMARC een geslaagde check aan uw From-domein kan koppelen.
NovaMX MailControl biedt SPF-flattening los of in een MailControl-bundel. Tarieven staan op de prijspagina. De uitleg is SPF-flattening uitgelegd.
DKIM: de handtekening op het bericht
DKIM voegt een cryptografische handtekening toe aan geselecteerde headers en de body. Ontvangers halen de publieke sleutel uit DNS (een selector, bijvoorbeeld selector._domainkey.uwdomein) en controleren dat het bericht niet is gewijzigd.
Een DKIM-slag helpt alleen tegen spoofing wanneer het ondertekenende domein overeenkomt met het zichtbare From-domein. Een nieuwsbriefplatform dat met een eigen domein tekent, terwijl uw merk in From staat, blijft voor DMARC nepmail tot u dat uitlijnt. Lees Wat is DKIM?.
DMARC: het beleid dat ontvangers om actie vraagt
DMARC koppelt SPF of DKIM aan het From-domein (alignment) en publiceert wat ontvangers moeten doen als beide falen. Het record staat op _dmarc.uwdomein.
p=none monitort alleen. Ontvangers leveren falende mail nog af. Dit stopt spoofing niet. Hier begint u, zodat u legitieme afzenders ziet voordat u iemand blokkeert.
p=quarantine vraagt ontvangers falende mail als verdacht te behandelen, vaak de spammap.
p=reject vraagt ontvangers falende mail te weigeren. Dit is de instelling die nepmail vanaf uw exacte domein echt vermindert.
Te vroeg naar reject gaan, voordat elke echte afzender alignment haalt, blokkeert facturen, tickets en nieuwsbrieven die u nog nodig heeft. Lees Wat is DMARC? en de stappengids.
DMARC RUA: wie namens u verzendt
RUA is het rapportadres in het DMARC-record (rua=mailto:...). Ontvangers sturen aggregaat-XML, meestal één keer per dag, met welke IP-adressen uw domein gebruikten en of SPF en DKIM aligned waren. RUA blokkeert geen mail. Zonder RUA gokt u welke systemen nog namens u verzenden.
RUF is het optionele forensische adres. De meeste organisaties beginnen alleen met RUA. MailControl DMARC Reports host het RUA-adres en maakt van de XML bronlijsten. Lees Wat is DMARC RUA? en DMARC Reports uitgelegd.
BIMI, MTA-STS en TLS-RPT
Deze staan naast authenticatie. Ze vervangen die niet.
BIMI kan uw logo tonen in ondersteunende inboxen. Streng DMARC is meestal een voorwaarde. Zie Wat is BIMI?.
MTA-STS vraagt andere servers TLS te gebruiken wanneer zij mail bij u afleveren. Het beschermt het transportpad, niet het From-adres. Zie Wat is MTA-STS?.
TLS-RPT is de rapportstroom voor TLS-fouten, los van DMARC RUA.
Hoe NovaMX MailControl helpt
MailControl is de mailauthenticatiemodule in My NovaMX. Na domeinverificatie bestelt u SPF-flattening, DMARC-rapportage, een begeleid pad van monitor naar reject, BIMI en MTA-STS, of een bundel die ze combineert. De website mag blijven waar die staat. U publiceert DNS waar de zone al leeft, of laat NovaMX DNS de records publiceren wanneer wij de zone hosten.
Begin met de gratis mailcheck om te zien wat het publieke internet al ziet. Lees daarna MailControl uitgelegd om Free, één add-on of een bundel te kiezen. Actuele tarieven staan op de prijspagina.
Een praktische volgorde
Publiceer één SPF-record dat onder tien lookups blijft. Gebruik SPF-flattening als de include-boom al te diep is.
Onderteken echte uitgaande stromen met DKIM en lijn het ondertekenende domein uit met From.
Publiceer DMARC op p=none met een RUA-adres dat u echt leest.
Herstel elke legitieme bron die alignment faalt.
Ga naar quarantine en daarna reject wanneer de rapporten schoon zijn.
Veelgestelde vragen
Wat is e-mail spoofing?
E-mail spoofing is het vervalsen van het zichtbare From-adres, zodat een bericht lijkt te komen van een domein dat de verzender niet beheert. Nepmail en fake email zijn de alledaagse namen voor dezelfde truc.
Stopt DMARC alle nepmail?
Afgedwongen DMARC (quarantine of reject) vraagt ontvangers mail te wantrouwen die SPF- of DKIM-alignment voor uw exacte domein faalt. Het stopt geen lookalike-domeinen, trucs met de weergavenaam, of mail vanaf een gekraakte echte mailbox.
Wat is DMARC RUA?
RUA is het adres in uw DMARC-record dat aggregaatrapporten ontvangt. Die rapporten tonen welke systemen mail met uw domein verstuurden. Ze blokkeren zelf geen mail.
Wat is SPF-flattening?
SPF-flattening houdt uw afzenderlijst onder de limiet van tien DNS-lookups, zodat SPF blijft slagen. Het weigert nepmail niet vanzelf. Het houdt SPF bruikbaar zodat DMARC erop kan steunen.