Deliverability

Why am I getting mail delivery failures for email I never sent?

Bounces for emails you never sent are almost always backscatter from someone spoofing your address. Here is how to tell it is not a hack, and how a strict DMARC policy makes it stop.

September 28, 2026 · 5 min read

You open your inbox and find bounce messages — “Mail delivery failed: returning message to sender” — for emails you never sent, often to people you’ve never heard of. It feels like your account was hacked. Almost always, it wasn’t. You’re seeing backscatter.

This is one part of the bigger picture. For how to read any bounce, status codes, and the full fix, see the complete guide: Mail delivery failed: returning message to sender.

What’s actually happening

Email lets anyone type anything into the “From” field — the protocol never checked it by default. Spammers exploit that: they put your address in the From line and blast thousands of messages. Every recipient server that rejects one generates a bounce and mails it back to the forged sender — you. Your mailbox was never touched; your address was borrowed as a disguise.

Spammer forges your address Stranger’s server rejects ✕ Another server rejects ✕ A third server rejects ✕ Your inbox fills with bounces
Backscatter: the spammer wears your address as a mask, and every rejection is mailed back to you.

How to tell it’s backscatter and not a breach

  • The bounces are for messages you have no record of in your Sent folder.
  • They’re addressed to random strangers, often in a burst over a day or two.
  • Your account shows no unfamiliar logins, and your real sending still works.

If you do see strange logins or your contacts report spam from you personally, that’s a different problem — change your password and enable two-factor authentication immediately.

How to make it stop

You can’t stop spammers from typing your address, but you can make the world’s mail servers reject anything that isn’t really from you. That’s exactly what SPF, DKIM and a strict DMARC policy do.

1 SPF Who may send Lists the servers allowed to send from your domain. 2 DKIM Proof of integrity Adds a signature proving the message was not altered. 3 DMARC The policy Tells servers what to do with fakes: reject or quarantine.
SPF authorises, DKIM signs, DMARC enforces. A strict DMARC policy is what stops forgeries in your name.
  1. Publish SPF and DKIM for your domain so legitimate mail is provably yours.
  2. Publish DMARC and move it to p=reject once you’ve confirmed your real mail passes. This tells receivers to throw away forgeries instead of bouncing them.
  3. Point DMARC’s rua= at an inbox so you get reports showing who’s trying to spoof you.

Don’t auto-delete the bounces yet. A filter that trashes everything from mailer-daemon will also hide real delivery failures. Fix DMARC first; the backscatter dries up on its own once forgeries get rejected upstream.

Full walkthrough of the three records is in our SPF vs DKIM vs DMARC guide, and if some of the bounces look like they want you to click something, read how to spot a fake delivery-failure message.

Related reading

Fix email delivery on your site

SecureSMTP delivers WordPress, Shopify, and custom form emails with SPF + DKIM + DMARC alignment. Free tier covers most small sites.