> For the complete documentation index, see [llms.txt](https://notes.programmersecurity.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.programmersecurity.com/phishing-and-real-world-stuff/email-spoofing.md).

# Email Spoofing

We can use **spoofy** to find out Weak Email Security, Weak email security (SPF, DMARC and DKIM) may allow us to spoof emails to appear as though they’re coming from their own domain.  [Spoofy](https://github.com/MattKeeley/Spoofy) is a Python tool that can verify the email security of a given domain.

<https://github.com/MattKeeley/Spoofy>

<figure><img src="/files/JCz3pcnTtrQOCDJixdw4" alt=""><figcaption></figcaption></figure>
