Email Spoofing vs Email Compromise: Why the Difference Decides Your Response
September 16, 2026
One means someone is imitating you. The other means someone is inside your mailbox. The response, cost, and reporting duties are completely different.
These two get used interchangeably, and the confusion is expensive — because one is a brand and filtering problem, and the other is a data breach.
Spoofing
Someone sends mail that appears to come from your domain or from a lookalike of it. They never touch your systems. There is no unauthorized access, no data exposure, and usually no notification obligation. Your recipients see the effects; your logs show nothing unusual.
Response: publish and enforce SPF, DKIM, and DMARC (move DMARC to quarantine, then reject). Monitor DMARC aggregate reports. Register or monitor obvious lookalike domains. Warn affected customers. Tune inbound impersonation protection so a lookalike aimed at you is tagged.
Compromise
An attacker has authenticated as your user and is inside the mailbox. There is unauthorized access to data, potential exposure of everything in the mailbox, and a real possibility of notification duties.
Response: revoke sessions and tokens, remove persistence, preserve audit logs, scope the data accessed, and involve counsel and your carrier. This is the first-hour sequence.
How to tell which one you have
Look at authentication logs, not at the message. A successful sign-in from unfamiliar infrastructure, a new forwarding rule, or a new consent grant means compromise. Message headers showing a different sending domain, with clean sign-in logs, means spoofing. If the fraudulent thread appears in the sent items of a real mailbox, it is compromise.
Why it matters legally
Notification obligations generally hinge on unauthorized access to personal information. Spoofing normally involves none of your data; compromise usually involves a mailbox full of it. Getting the classification wrong in either direction — reporting a spoof as a breach, or a breach as a spoof — creates its own problem. See email breach notification requirements.
Both can happen at once, and often do: a lookalike domain is a common exit strategy after a mailbox is contained.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.