The easiest way to spoof mails is if the evil-doer finds a mail server that has an open SMTP port. SMTP (Simple Mail Transfer Protocol) lacks authentication so servers that are poorly configured in this way are prey to abusers. There is freely available software that will allow you to use any sender address you like. There are a few attempts to enforce rules that could accomplish this: SPF (Sender Policy Framework) or DKIM (Domain-based Message Authentication, Reporting, and Conformance)”]
Source: https://blog.malwarebytes.com/cybercrime/2016/06/email-spoofing/

