A phishing message can say it is from your bank, your accountant, or your own address. The From line is just text the sender typed — email was designed in an era of trust, and the visible From header carries no guarantee at all.
Wolf Mail Shield shows you the True Sender: the address the message actually came from. When “From” says your bank and True Sender says a server in another country, you know in a second.
The order of evidence
Real identity comes from the authentication recorded as the message travelled — SPF (was this server allowed to send for that domain?), DKIM (was it cryptographically signed, and by whom?) and DMARC (does the domain’s policy say it should pass?). Wolf Mail Shield answers “who sent this?” using the strongest evidence available:
- The DKIM signing domain — cryptographic proof of who signed it.
- The SPF-verified envelope sender — the return path it actually travelled under.
- The connecting IP — which machine handed it over.
- The From header — only if nothing better exists, and labelled as unverified.
Critically, a From address matching your own is treated as proof of forgery, not identity. Nobody emails themselves. The envelope sender is used instead, so a spammer cannot make the tool accuse you of sending their mail.