Email spoofing forges the From: header to make email appear from a trusted sender. Used in BEC, phishing, and malware distribution.
DMARC/SPF/DKIM together prevent spoofing of your own domain. But they don't prevent spoofing of domains you don't control. User education: verify unexpected requests out-of-band, especially financial.