---
title: How can I use From Header Screening to expose spoofed email?
description: MDaemon 20+ includes an updated From Header Modification feature to help expose spoofed messages.
---

[Skip to content](https://knowledge.mdaemon.com/from-header-screening-configuration#main-content)

[![](https://knowledge.mdaemon.com/hs-fs/hubfs/MDaemon-Technologies_logo.png?width=200&height=150&name=MDaemon-Technologies_logo.png)](https://mdaemon.com/)

- [Knowledge Base Home](https://knowledge.mdaemon.com/)
- [Go to www.mdaemon.com](https://mdaemon.com/)

Open main navigation

Close main navigation

- [Knowledge Base Home](https://knowledge.mdaemon.com/)
- [Go to www.mdaemon.com](https://mdaemon.com/)
- [Contact Us](https://mdaemon.com/pages/contact-us)

[Contact Us](https://mdaemon.com/pages/contact-us)

 Knowledge Base

- There are no suggestions because the search field is empty.

1. [Knowledge Base Home](https://knowledge.mdaemon.com/?hsLang=en)
2. [MDaemon Email Server](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en)

# How can I use From Header Screening to expose spoofed email?

## MDaemon versions 20 and above include an updated From Header Modification feature to help expose spoofed messages that are trying to trick users into thinking the email is from a legitimate source.

Navigate to the From Header Screening menu:

1. Select **Security**
2. Select **Security Manager**
3. Expand **Screening**
4. Select **From Header Screening**

### **Option 1**

The first option will modify the from header and insert the actual email address into the display name. 

![from\_header\_modification\_opt1-1](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_modification_opt1-1.png?width=413&height=184&name=from_header_modification_opt1-1.png)

**Example:**

A message is received with the following from headers from a spammer spoofing "Legit User" in the from header. 

From: "Legit User" \<spammer@spam.com\>  
To: "User01" \<user01@company.test\>  
Subject: From Header Screening 

For this example, Outlook's Message List view shows the display-name only when it exists. The display name is the text in between the quotes in the header. The spammer@spam.com address is not displayed. 

![from\_header\_screening\_1\_spam](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_screening_1_spam.png?width=444&height=71&name=from_header_screening_1_spam.png)

When **Add email address to display-name** is enabled, the from header above will be modified into the header below.

From: "Legit User (spammer@spam.com)" \<spammer@spam.com\>

![from\_header\_screening\_1\_1-1](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_screening_1_1-1.png?width=448&height=71&name=from_header_screening_1_1-1.png)

An alternate option is to select **Put email address before name** is selected to insert the address to the beginning of the header and place the display name in the parenthesis.

FROM: "spammer@spam.com (Legit User)" \<spammer@spam.com\> 

![from\_header\_screening\_1\_1-2](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_screening_1_1-2.png?width=448&height=68&name=from_header_screening_1_1-2.png)

### **Option 2**

With **Replace mismatched email address in display-names with real ones** is selected, MDaemon compares the address in the display-name against the actual address.  If a spammer inserts a legitimate address in the display-name section of the from header to disguise/spoof the spammers actual address, MDaemon will remove the address in the display name and insert the actual address.

![from\_header\_modification\_opt2](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_modification_opt2.png?width=419&height=92&name=from_header_modification_opt2.png)

**Example:**

A message arrives with the [spammer@spam.com](mailto:spammer@spam.com) spoofing user02@company.test.

From: "user02@company.test" \<spammer@spam.com\>  
To: "User01" \<user01@company.test\>  
Subject: From Header Screening

Using Webmail for this example, the above headers will display the message as follows.

![from\_header\_screening\_2-1\_webmail](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_screening_2-1_webmail.png?width=629&height=99&name=from_header_screening_2-1_webmail.png)

With **Replace mismatched email address in display-names with real ones** selected, the message would appear as below.

![from\_header\_screening\_2-2\_webmail](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_screening_2-2_webmail.png?width=626&height=100&name=from_header_screening_2-2_webmail.png)

(Optional) Select **Do not apply these features to authenticated messages** to prevent authenticated sessions from having the from header modified.

Keep in mind when this option is checked, if an account is compromised, an entity submitting spam as this user can still disguise the actual email address behind the display-name. 

Click **Exempt List** to bring up a window to enter addresses messages are addressed To that should bypass the From Header Screening options.

![from\_header\_modification\_exempt](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/from_header_modification_exempt.png?width=571&height=482&name=from_header_modification_exempt.png)

- [MDaemon Email Server](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en#main-content)

    - [Mobile Device Management](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en#mobile-device-management)
- [MDaemon AntiVirus (SecurityPlus)](https://knowledge.mdaemon.com/mdaemon-antivirus-securityplus?hsLang=en)
- [ActiveSync for MDaemon](https://knowledge.mdaemon.com/activesync-for-mdaemon?hsLang=en)
- [MDaemon Connector for Outlook (Outlook Connector)](https://knowledge.mdaemon.com/mdaemon-connector-for-outlook-outlook-connector?hsLang=en)
- [SecurityGateway for Email Servers](https://knowledge.mdaemon.com/securitygateway-for-email-servers?hsLang=en)
- [RelayFax Network Software](https://knowledge.mdaemon.com/relayfax-network-software?hsLang=en)

[![Chill listening crop-3](https://knowledge.mdaemon.com/hs-fs/hubfs/belch.io/template-assets/MDaemon-Technologies_logo.png?width=199&height=41&name=MDaemon-Technologies_logo.png "Chill listening crop-3")](https://www.mdaemon.com)

[Knowledge Base Home](https://knowledge.mdaemon.com?hsLang=en)

<https://www.youtube.com/c/MDaemonTechnologies> <https://www.linkedin.com/company/mdaemon-technologies/> <https://www.facebook.com/MDaemon.Technologies/> <https://www.twitter.com/MDaemon_Email>

Copyright © 2025, MDaemon Technologies