With the way that SMTP works, anyone anywhere can specify any email address as their From address as long as they have a mail server that allows them to do so. From address may be completely false or even non-existent.
Note: There is no way to prevent other people from using your email address when they are using a different mail server.
In general, there are two situations that can make you aware that your email address was spoofed:
- You receive bounce back emails or replies to messages you didn't send:
There is no way to prevent the bounce back messages from coming to you. If a message gets returned to the sender, it goes to the actual holder of the From address, regardless of who sent it. Similarly, when someone replies to a message, it always goes to the reply-to address.
- You receive messages with your email address in the From field (or in both To and From fields):
Make sure that your domain and/or email address is not whitelisted either in Outlook/OWA.
- Remove your domain from Advanced Email Security Safe Senders List.
Note: some spammers can specify you address as both From and To addresses, so you will receive the message in any case (even if it bounces).
Read the Wikipedia® article on Backscatter (e-mail) for more information about backscattering.
Failed SPF validation will add supplementary spam score to the spoofed email and this will increase the chances that this email will be delivered to Junk.
Read the Knowledge Base article on What is an SPF record? What do I need to do about it? for more information.
With Advanced Email Security, you have the following options to block messages with a forged From address which might be, in fact, your own email address or some inexistent email address at your domain.
- If you have only Exchange mailboxes on the account you may want to add your own domain to Blocked Senders list. This action won't affect internal mail flow since mail delivery between internal users isn't filtered.
- If you have Exchange mailboxes and also have SMTP-applications (e.g. printer, web form, etc.) sending mail to the users on the account, you still can add your own domain to Blocked Senders list, but make sure you added From email address or IP address of the application to Safe Senders.
- If a part of the users on the account have POP/IMAP mailboxes, blocking your own domain won't be the best option, because you will need to add all existent mailboxes to Safe senders list. This technique has its drawback: spoofed emails which appear as coming from existed email address on the account won't be blocked as such email addresses will be added to Safe Senders list. So this option is useful only if you receive spoofing from
inexistentemail address at your domain.