Site AI Auditby Internet Solutions

Backscatter: Why You Get Bounces for Emails You Never Sent

2026年9月29日8分で読めますメール到達率
Backscatter: Why You Get Bounces for Emails You Never Sent

Short answer: Backscatter is the flood of bounce messages, auto-replies and “undeliverable” notices you receive for e-mails you never sent. It happens when spammers forge your address as the sender, and some receiving servers send their rejection back to the forged address instead of refusing the message outright. First check the bounced message’s headers to confirm it did not come from your own systems. Then publish SPF, DKIM and a DMARC policy so receivers can reject forged mail, and make sure your own server never produces backscatter itself.

What backscatter looks like

You open your inbox and find dozens or hundreds of messages titled “Undelivered Mail Returned to Sender”, “Delivery Status Notification (Failure)” or “Out of office” replies, often in languages you do not speak and addressed to people you have never contacted. Each one quotes or attaches a message that seems to come from your address, usually spam or a phishing attempt.

It is alarming, and the natural first thought is that your account has been hacked. Sometimes it has. More often, nobody touched your account: someone simply wrote your address into the sender field of their spam.

Why it happens

The e-mail system was designed at a time when sender addresses were not verified. Anyone can put any address in the envelope sender (the Return-Path, where bounces go) and in the visible From line. Spammers use real domains to make their messages look more legitimate and to keep bounces away from themselves.

When the spam reaches a receiving server, one of two things happens:

Auto-responders add to the problem. An out-of-office reply or a ticket system confirmation sent in response to spam also goes to the forged address. The result is backscatter: side-effect mail aimed at an innocent third party.

Backscatter vs genuine bounces

Not every unexpected bounce is backscatter, and it is important not to filter away real problems. Genuine bounces relate to messages you or your systems actually sent: an invoice to a customer whose mailbox is full, a newsletter to an address that no longer exists, a reply rejected because of a policy at the recipient’s side. They quote your real message, with your normal subject and content, and they usually arrive one at a time.

Backscatter has a different pattern:

Genuine bounces tell you something about your own mail and deserve attention; the guide to email bounce codes explains how to read them.

Step 1: check whether you actually sent it

Before assuming spoofing, rule out a real compromise. Open one of the bounces and look at the original message it contains, especially its full headers. Our guide to reading email headers shows how.

  1. Look at the first Received lines of the original message. Did it pass through your mail provider’s servers, or through unknown servers elsewhere?
  2. Check authentication results in the bounce, if included. A forged message typically shows SPF fail or softfail and no valid DKIM signature for your domain.
  3. Look in your Sent folder and your mail provider’s message trace or logs for the messages in question.
  4. Review sign-in activity in your mail account for unfamiliar locations or devices.
  5. Check your website’s forms and scripts. A contact form or old script abused by bots can send real mail from your server, which is a compromise of a different kind.

If the original went through your own systems, treat it as a security incident: change passwords, enable two-factor login, review mailbox forwarding rules and fix the abused form or script. If it did not, you are dealing with spoofing and backscatter.

Step 2: make forged mail easier to reject

You cannot stop spammers from typing your address, but you can tell receivers clearly that such messages are forged, so more of them reject the spam during the SMTP conversation instead of accepting and bouncing it.

DMARC also gives you aggregate reports, which show the volume of forged mail using your domain and where it comes from. That helps confirm whether a wave of backscatter matches a spoofing campaign. More on stopping impersonation is in how to stop people sending mail as your domain.

Authentication does not eliminate backscatter completely. Some servers still accept first and bounce later, ignoring the policy. But it significantly reduces the number of forged messages that are accepted, and with them the bounces.

Step 3: filter the backscatter you still receive

Waves of backscatter usually last from a few hours to a few days, following the spam campaign that caused them.

Step 4: make sure you are not a source of backscatter

Servers that generate backscatter harm innocent people and can end up on blocklists, some of which specifically track backscatter sources. If you manage a mail server, or your website sends automatic replies, check these points:

SettingBackscatter riskBetter practice
Accept mail for any address, bounce laterHighValidate recipients and reject during SMTP
Catch-all mailbox that forwards or bouncesMediumAccept only real addresses, or quarantine without replying
Out-of-office replies to every senderMediumReply only to contacts or internal senders; skip mail marked as spam
Help desk auto-acknowledgementsMediumDo not respond to messages that fail authentication or look like spam
Spam filtering after acceptance, with bounceHighReject during SMTP, or quarantine silently

If you suspect your server’s IP has been listed for backscatter or spam, see how to check blocklists and get delisted.

Domains that never send mail

Unused and parked domains are popular for spoofing precisely because nobody watches them. If a domain does not send e-mail, publish an SPF record of v=spf1 -all, a DMARC policy of p=reject and, ideally, a null MX record. That tells receivers to refuse all mail claiming to come from it, which cuts both spoofing and backscatter. The full setup is in how to protect parked and unused domains.

How Site AI Audit helps

Site AI Audit checks your domain’s e-mail authentication as part of a full website check: SPF and its lookup limit, DKIM signatures, the DMARC policy and MX records, alongside SEO, speed, SSL and security headers. Findings are explained in plain words and ranked by impact, so a missing or weak DMARC policy, the most common reason spoofing goes unchecked, is easy to spot. Start with a free check; paid plans on the pricing page add monitoring and alerts.

Related reading

The bottom line

Backscatter is the echo of someone else’s spam: bounces and auto-replies aimed at your address because spammers forged it. Check the headers to rule out a real compromise, publish SPF, DKIM and an enforcing DMARC policy so receivers reject forgeries, filter what still arrives, and make sure your own systems reject bad mail during delivery instead of bouncing it to innocent people.

FAQ

Why am I getting bounce messages for emails I did not send?

Spammers have most likely forged your address as the sender. Some receiving servers accept their spam and then send the bounce to the forged address, which is yours. This is called backscatter.

Does backscatter mean my email account was hacked?

Not necessarily. Check the original message headers, your Sent folder and your sign-in activity. If the message did not pass through your mail servers, it was spoofed rather than sent from your account.

Does DMARC stop backscatter?

It reduces it. With an enforcing DMARC policy, receivers that honour it reject or quarantine forged mail instead of accepting and bouncing it. Some badly configured servers may still send bounces.

How long does a backscatter wave last?

Usually from a few hours to a few days, following the spam campaign that used your address. Filtering rules help you handle it while it lasts.

Can my own server cause backscatter?

Yes, if it accepts mail for non-existent addresses and bounces it later, or sends auto-replies to spam. Reject bad mail during the SMTP session and limit auto-replies.

#DMARC#Email Authentication#Email Security#Troubleshooting
あなたのWebサイトも無料で診断。Webサイトで直すべき点と、どこから始めるべきか。
無料で始める

ブログの他の記事

すべての記事 →
Internet Solutions

私たちのその他のサービス

Internet Solutions が開発。ほかの製品もぜひお試しください。それぞれ違う形で時間を節約できます。

internet-solutions.net ↗
Site AI Audit
プライバシーの概要

当サイトは、最高のユーザー体験をご提供するためにCookieを使用しています。Cookie情報はブラウザに保存され、再訪問時の識別や、サイトのどのセクションが興味深く役立つかを私たちのチームが理解するのに役立ちます。