You open your inbox and find bounce messages — “Mail delivery failed: returning message to sender” — for emails you never sent, often to people you’ve never heard of. It feels like your account was hacked. Almost always, it wasn’t. You’re seeing backscatter.
This is one part of the bigger picture. For how to read any bounce, status codes, and the full fix, see the complete guide: Mail delivery failed: returning message to sender.
What’s actually happening
Email lets anyone type anything into the “From” field — the protocol never checked it by default. Spammers exploit that: they put your address in the From line and blast thousands of messages. Every recipient server that rejects one generates a bounce and mails it back to the forged sender — you. Your mailbox was never touched; your address was borrowed as a disguise.
How to tell it’s backscatter and not a breach
- The bounces are for messages you have no record of in your Sent folder.
- They’re addressed to random strangers, often in a burst over a day or two.
- Your account shows no unfamiliar logins, and your real sending still works.
If you do see strange logins or your contacts report spam from you personally, that’s a different problem — change your password and enable two-factor authentication immediately.
How to make it stop
You can’t stop spammers from typing your address, but you can make the world’s mail servers reject anything that isn’t really from you. That’s exactly what SPF, DKIM and a strict DMARC policy do.
- Publish SPF and DKIM for your domain so legitimate mail is provably yours.
- Publish DMARC and move it to
p=rejectonce you’ve confirmed your real mail passes. This tells receivers to throw away forgeries instead of bouncing them. - Point DMARC’s
rua=at an inbox so you get reports showing who’s trying to spoof you.
Don’t auto-delete the bounces yet. A filter that trashes everything from mailer-daemon will also hide real delivery failures. Fix DMARC first; the backscatter dries up on its own once forgeries get rejected upstream.
Full walkthrough of the three records is in our SPF vs DKIM vs DMARC guide, and if some of the bounces look like they want you to click something, read how to spot a fake delivery-failure message.