A system, method and computer program product are provided for identifying
spoofed emails. According to the method, an email addressed to a
recipient in a first network is received, with the email including a
plurality of headers, and at least one of the plurality of headers
including a sender address. It is determined whether the sender address
indicates a mailbox from within the first network, and the sender address
is modified if it indicates a mailbox within the first network. The email
with the modified sender address is sent to the recipient. In one
embodiment, a second email is received that is from the recipient and
that is addressed to the modified sender address, the modified sender
address is modified so as to return it to its original form, and the
second email is sent.