← All posts post

The Spoofing Timeline

SpoofingOctober 2026 · 1 min read

Spoofed mail got past controls that were supposed to stop it. The question was simple: why didn't anything block this?

The answer wasn't simple.

I rebuilt the timeline across three layers:

  • Exchange transport behavior: how the mail actually moved
  • SPF, DKIM and DMARC results: what each check said, message by message
  • Composite authentication: the verdict rolled up from all of it

Somewhere between those layers, the controls everyone assumed were working didn't behave the way anyone expected. Isolating exactly where took evidence, not instinct.

And this isn't rare. EasyDMARC's 2026 report looked at the 1.8 million most-visited domains worldwide: about 52% have a valid DMARC record, and less than a quarter actually enforce it with quarantine or reject.

p=none is a security camera nobody's watching. It records the spoof. It doesn't stop it.

Most orgs believe they're protected from spoofing because they "set up email security." Very few could tell you which layer would actually stop it. That gap is where attackers live, and finding it is my favorite part of the job.

Sources

  1. EasyDMARC 2026 DMARC Adoption Report