Email Spoofing Attempts Are Surging
August 4, 2026 · Attila Domokos · 2 min read
RefineEmail has been monitoring a middle school's email domain for about a year.
Reaching full protection was a long journey. Before moving the domain from monitoring to enforcement, we had to identify every authorized sending source and ensure each one was properly authenticated. We completed the rollout gradually and reached full DMARC protection late last year.
Then the first quarantined spoofing attempt appeared. Then five more. And then the numbers kept climbing.
The year began with a relatively low volume of spoofing attempts, but as the weeks progressed, we noticed a significant increase. Looking at the data in weekly snapshots, here is what we found:

Attackers are already trying to impersonate trusted organizations. The only question is whether the email domain is configured to stop them.
This pattern is not unique to schools. We are seeing similar increases among customers in other industries.
It is not surprising: AI makes it easier for malicious actors to create convincing emails at scale. They can impersonate an organization’s domain and send realistic-looking messages to potential victims.
In this school's case, these unauthorized emails are being sent to spam because the domain’s DMARC policy is fully enforced.
Without an enforced DMARC policy, attackers can spoof your domain and send emails that appear to come from your organization. Depending on the recipient's email provider and security controls, some of those messages may reach the inbox.
Is your email domain protected?
Check it here: https://refineemail.com/score