Spotting domain spoofing through legitimate email forwarders
Most office workers in Sydney and Melbourne have a colleague who forwards their mail while on long service leave. That routine habit, however, sits at the centre of a growing fraud problem. Cybercriminals now exploit trusted forwarding services to slip spoofed messages past filters that would normally block outright impersonation.
When a familiar forwarder relays a message, the receiving server sees a legitimate intermediary in the chain. The original sender may be an attacker using your domain, but the bounce-back, the routing path and the visible "on behalf of" tag all point to a known service. Detecting that manipulation requires looking past the friendly envelope and into the cryptographic and routing details that most inboxes hide by default.
The technical puzzle is solvable without becoming a forensic analyst. By checking SPF results, DKIM signatures and DMARC alignment together, then layering behavioural analysis on top, Australian organisations can separate genuine forwarded mail from fraudulent spoofs that abuse the same channels.
How email forwarding changes message headers
Every forwarded message accumulates new headers. A typical chain might start with the original sender, pass through a corporate relay in Brisbane, then arrive at a Gmail account in Perth. Each hop adds a Received line, a new Authentication-Results block and, often, a rewritten envelope sender. The original DKIM-Signature is preserved, but SPF is evaluated against the new relay rather than the original domain.
Forwarders such as mailing list managers, university alumni gateways and consumer services like Apple Hide My Email rewrite addresses to keep internal routing invisible. These rewrites are perfectly legal and widely used, yet they alter the message in ways that spoofers love to mimic. A fake "on behalf of" line costs nothing to forge, while the cryptographic gap it creates is often the only reliable giveaway.
SPF failures when forwarders relay mail
Sender Policy Framework relies on the connecting IP matching an authorised list in the domain's DNS record. The moment a Sydney clinic's mail gets routed through a third-party forwarding service in Singapore, SPF breaks. The receiving server sees an unfamiliar IP and records a softfail or fail, even though the message is genuine.
The reverse situation is more dangerous for detection. A spoofed email sent directly from an attacker's server will trigger an SPF fail for the impersonated domain, but if that message is then relayed through a legitimate forwarder that rewrites the envelope, the new SPF check references the forwarder, not the attacker. The original failure disappears from the visible header unless you trace the full chain. Tools that surface the first hop, rather than the last, expose this laundering effect.
DKIM signature breakage after forwarding
DKIM survives most forwarding because the body and selected headers are signed, not the routing path. Some forwarders, however, modify the Subject line for tagging, add a List-Id header or strip attachments in ways that invalidate the signature. A legitimate user in Adelaide forwarding to a colleague overseas may suddenly see dkim=fail appear in the header, with no idea why.
Spoofers rely on this confusion. They craft a message that passes DKIM for a domain they control, then route it through a well-known forwarder to obscure the signing context. The receiving mail server sees a valid signature from the forwarder's subdomain and trusts the message. Manual inspection of the d= parameter in the DKIM-Signature header reveals whether the signing domain matches the visible From address. The SPF, DKIM and DMARC reputation checklist walks through this verification step by step.
DMARC alignment checks as your first filter
DMARC ties SPF and DKIM results back to the domain shown in the From header. A message that passes DKIM for mail.forwarder.com but shows accounts@yourbank.com.au in the visible From field will fail alignment. This is the single most reliable automated signal for catching domain spoofing that hides behind a forwarder.
Australian organisations that have published DMARC records at p=reject report dramatic drops in fraudulent mail reaching staff inboxes. Even a quarantine policy buys time, since messages land in junk folders rather than inboxes where an employee might click on a fake ATO refund link. Reviewing aggregate reports from your DMARC provider shows exactly which forwarders are authenticating on your behalf and which are failing, helping you build an explicit allowlist.
Analysing Reply-To and Return-Path discrepancies
Spoofers often match the visible From address but change the Reply-To to an address they control. When the recipient hits reply, the conversation leaves the spoofed domain and lands in the attacker's mailbox. Forwarding services complicate this picture because they routinely set their own Reply-To for unsubscribe handling.
The Return-Path header offers a cleaner signal. For a legitimate forwarder, this should align with the forwarder's own domain or your domain if you have configured SRS (Sender Rewriting Scheme). A Return-Path pointing to a free webmail provider, an unrelated corporate domain or a freshly registered host is a strong indicator of spoofing layered on top of forwarding. Comparing these values against the advertised From address is a quick manual check worth teaching to frontline staff.
Behavioural red flags in forwarded conversations
Technical checks only go so far. A forwarded message that arrives outside business hours, references an unfamiliar supplier or includes urgent payment instructions for an Australian Business Number you have never dealt with deserves closer scrutiny. Many Perth-based mining firms have reported invoice fraud schemes that arrive via compromised forwarding accounts belonging to long-term vendors.
Train staff to treat forwarded mail with the same scepticism as ordinary external mail, even when the original sender appears to be a colleague. Hover over links before clicking, confirm requests through a separate channel and pay attention to subtle tone shifts that suggest an attacker wrote the body. These habits catch spoofs that pass every cryptographic test simply because the attacker obtained valid forwarding credentials.
Combining tools and reputation checks for certainty
No single header reveals everything. Pair your authentication checks with domain reputation lookups that score the forwarder against known spam and phishing activity. Free platforms aggregate sending patterns across millions of messages, making it easy to spot a forwarder that has only recently started relaying mail for your domain.
For high-volume environments, bulk checks and API access let security teams automate the process and feed results into SIEM dashboards. The how to use guide explains how to run individual lookups and integrate them into incident response playbooks. Under Australia's Notifiable Data Breaches scheme, organisations that detect spoofing early can mitigate harm before it escalates into a reportable incident, making proactive verification a compliance asset as much as a security one.