A bounce notice landed in my inbox recently.
The subject line read "Contact Request."
The sender was listed as me.
I never sent it.
What Happened
Someone else's website, a completely unrelated business with no connection to anything I run, had a contact form or mail script that got compromised, or was simply built in a way that made this kind of abuse possible. Whoever sent this message used that script to blast out a scam, the classic too-good-to-be-true lure, a luxury car for a fraction of its value, with a shortened link leading wherever scam links lead.
To make the message look more legitimate, and to make sure any bounces or abuse complaints landed on someone else instead of them, they forged the From, Return-Path, and Reply-To headers to say my domain. Not my email account. Not my mail server. Just the text in a header field that, by itself, is trivially easy to fake.
This is called spoofing, sometimes referred to as a joe job in the older spam terminology, where a spammer borrows a real, uninvolved domain's name specifically because it looks more credible than something made up, and because any fallout lands on the innocent party instead of the one responsible.
Why This One Bounced Back To Me
The script sending this message failed to include a recipient address. No To field. That is a broken, sloppy implementation on the sending end, and it meant the message never had anywhere to go. The mail server handling it rejected it outright, and because the forged Return-Path pointed at my domain, the rejection notice came straight back to me.
If that script had been built correctly, this message would have gone out, landed in someone's inbox, with my domain sitting in the From field, and I would never have known it happened.
What This Could Have Meant Without The Right Setup
This is the part worth paying attention to. If my domain did not have proper email authentication in place, SPF and DMARC specifically, a spoofed message like this one has a real chance of landing in a recipient's inbox looking legitimate. Not flagged. Not quarantined. Just sitting there, claiming to be from me, pushing a scam.
That is the damage spoofing causes. Not to the spammer. To the domain whose name gets borrowed. Every recipient who got that message and checked who it was from would have seen my business name attached to a Rolls-Royce scam.
What Happened Instead
My domain has SPF configured with a hard fail policy, meaning it explicitly tells receiving mail servers that only specifically authorized sources are allowed to send mail claiming to be from me. Anything outside that list fails the check.
DMARC is set to quarantine, meaning any mail that fails those authentication checks gets routed to spam rather than delivered normally to a recipient's inbox.
For any real recipient whose mail provider enforces these standards, which covers the overwhelming majority of mail services people use, this message would never have reached a real inbox looking legitimate. It would have been quarantined, flagged, or rejected before a human saw it and wondered why my business was emailing them about a luxury car.
Here is the header of the email.
A message that you sent contained no recipient addresses, and therefore no delivery could be attempted. ------ This is a copy of your message, including all the headers. ------ To: Subject: Contact Request X-PHP-Script: diyamariyaenterprises.com/admin/index.php for 188.126.89.58 X-PHP-Filename: /home/diyamariya/domains/diyamariyaenterprises.com/private_html/admin/index.php Date: Sun, 4 Oct 2026 06:20:26 +0530 From: <contact@bizpinpro.com> Return-Path: <contact@bizpinpro.com> Reply-To: <contact@bizpinpro.com> User-Agent: CodeIgniter Enquiry Details Name: Marvinsaush Email: contact@bizpinpro.com Contact Number: 88817425555 Message: ENJOY MODERN INTERPRETATIONS OF CLASSICS IN A 2026 ROLLS-ROYCE PHANTOM FOR $15,000 >>> https://tau.lu/84e1d4587
Why This Is Worth Writing About
I have written before about why email authentication matters, in the trilogy covering SPF, DKIM, and DMARC. Most of that writing was necessarily theoretical, explaining the mechanism and the risk before anything had tested it.
This is what it looks like when the mechanism gets tested. A real spoofing attempt, using my domain name, hit the protections I had set up, and the only reason I know about any of it is that the sender's own script was broken enough to bounce the failure back to me. Most spoofed mail sent against a properly configured domain never gets seen by anyone. It gets quarantined silently, exactly as intended, and the business whose name got borrowed never finds out it happened.
The Foundation Connection
Email authentication is not a theoretical best practice. It is the difference between a scam quietly getting caught before anyone sees it, and a scam landing in someone's inbox wearing your business's name without your knowledge or consent.
I did not stop this message through anything I did in the moment. I stopped it months ago, when SPF and DMARC were configured correctly as part of building a proper Digital Foundation. The protection was already in place, quietly doing its job, long before anyone tried to abuse it.
Check your own domain's setup before you need it to work.
Most of the time, you will never know whether it did.