Explanation
Email spoofing is the creation of email messages with a forged sender address. Email spoofing is often an attempt to trick the recipient into making a damaging statement, opening a virus, or releasing sensitive information (such as passwords or credit card information). The terms spoofing and phishing should not be confused with each other; they are separate concepts but often go hand in hand.
Examples of how spoofed email is used include:
- Email claiming to be from a system administrator requesting users to change their passwords to a specified string and threatening to suspend their account if they do not do this.
- Email claiming to be from a person in authority requesting users to send them a copy of a file or other sensitive information.
- Email message with a link to a website which appears to be a legitimate website but is actually constructed for the purpose of illegally gathering private information such as passwords or bank account numbers. The link in the message may appear to be legitimate, but the actual URL is typically concealed using HTML code.
- Websites where you can "email yourself a link" or "send this to a friend" almost always spoof the sending address. For cases such as this, Information Technology recommends using a non-TTU email address such as Outlook (consumer version), Yahoo, or Gmail.
Spoofing is possible because email protocols were not originally designed with the ability to verify the identity of the message sender. TechMail administrators attempt to overcome this problem through the addition of multiple technologies and the latest industry standards. These technologies can often verify that a message claiming to be from a particular address was actually sent from that address. This means that you will usually not receive messages from spoofed addresses in your TechMail Inbox, particularly if they tried to spoof a TechMail address; these typically go to the Junk Email folder or are rejected for delivery altogether. You may still receive spoofed TechMail messages in your non-TTU email accounts, depending on whether those email providers follow industry standards like SPF, DKIM, and DMARC.
Sometimes, emails are sent where the recipient's address does not appear in the "To" or "Cc" lines, but instead it's on the "Bcc" line where it cannot be seen. In some of these cases, the sender may be attempting to trick the recipient into thinking they got the email by mistake. These are not necessarily spoofed emails, though they may be. It all depends on whether the sender's address was forged or not.