Someone emailed me from my domain

Got an email this morning from someone using my domain here on Cloudfare. They used “[email protected]” and I don’t have an email with “mail”, I just have one with my name and one with “[email protected]

How did they create this email? And how do I stop it now and prevent it in the future?

Anyone can send an email that claims to be from any address. It’s why email authentication practices like SPF, DKIM, and DMARC are so important. Here is a more in depth explanation from dmarcian.

Thank you. I have the email through Microsoft 365 and I’ll use what you sent me to check against what I have there.

