DMARC Engine
Home/Blog/Threats & fraud
Blog

Threats & fraud

21 articles

16 June 2026 · 11 min read

Display-name spoofing and why DMARC misses it

Friendly-from spoofing impersonates a person using a domain the attacker legitimately controls, so it passes DMARC every time by design. Here is why DMARC cannot catch it, where it shows up in BEC and CEO fraud, and the layered controls that actually mitigate it.

Read more
9 June 2026 · 12 min read

Reading your first DMARC aggregate report

A field-by-field walkthrough of a DMARC aggregate (RUA) XML report: metadata, source IPs, disposition, SPF and DKIM results, alignment, and spotting spoofers.

Read more
9 June 2026 · 11 min read

Protecting parked and no-mail domains

Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.

Read more
3 June 2026 · 12 min read

How invoice fraud begins with a spoofed domain

Invoice fraud usually starts with a forged sender address. Here is how exact-domain spoofing works, what DMARC at p=reject stops, and what it does not.

Read more
3 June 2026 · 16 min read

Dangling DNS records as an email risk

Stale CNAMEs, SPF includes and DKIM selectors that point to resources you no longer own quietly delegate your sending authority to whoever claims them next. Here is how dangling DNS becomes a real spoofing and SPF risk, and how to find and close the gaps.

Read more
1 June 2026 · 9 min read

Subdomain policy: the DMARC sp tag

An enforced root domain at p=reject protects exactly one address and can leave every subdomain spoofable. Here is what the DMARC sp tag does, the inheritance trap that catches teams mid-migration, and how to close the gap safely without bouncing legitimate subdomain mail.

Read more
31 May 2026 · 11 min read

How email spoofing actually works

Email spoofing takes no password and no exploit: SMTP simply trusts whatever the sender types into the From field. This guide traces the mechanism from the raw SMTP conversation, through the crucial split between the envelope-from used for delivery and the header-from a human reads, to the three layered controls (SPF, DKIM and DMARC alignment) that finally make forging your domain fail.

Read more
25 May 2026 · 11 min read

Lookalike and cousin domains

Attackers register confusable domains that authenticate perfectly and slip past your defences, because your DMARC policy protects only the exact name it is published under. Here is how homoglyph and cousin domains work, the precise reason a p=reject policy cannot touch them, and the layered plan that actually defends your brand.

Read more
23 May 2026 · 12 min read

PCI DSS 4.0, cyber-insurance and email authentication

PCI DSS 4.0 Requirement 5.4.1 and cyber-insurance questionnaires now treat anti-phishing as a measurable control. Here is exactly how that intersects with DMARC, SPF and DKIM, what counts as evidence, and how to reach enforcement without breaking your own mail.

Read more
22 May 2026 · 11 min read

Phishing and business email compromise

Business email compromise rarely uses malware: it borrows trust by impersonating people you already deal with. Here is how phishing and BEC work, where the money goes, and the layered defences, with DMARC at enforcement as the load-bearing wall.

Read more
10 May 2026 · 11 min read

What is DMARC and how does it work?

DMARC is the control that stops exact-domain spoofing. Here is what it is, how it builds on SPF and DKIM through alignment, what each policy value instructs receivers to do, and how to reach p=reject safely.

Read more
8 May 2026 · 13 min read

What is SPF and how does it work?

SPF lets you publish, in DNS, the list of servers allowed to send mail for your domain. Here is how the syntax works, what the all qualifier and each mechanism mean, what SPF actually authorises, the ten-lookup limit that catches everyone, and the spoofing gap that DMARC alignment closes.

Read more
22 April 2026 · 16 min read

Executive impersonation and CEO fraud

CEO fraud forges your leaders to authorise urgent payments. Enforced DMARC kills exact-domain spoofing outright, but leaves real gaps. Here is exactly what it stops, what it cannot, and the layers you need around it.

Read more
8 April 2026 · 13 min read

Gift card scams over email

Gift card BEC is business email compromise stripped to its cheapest form: no payload, just a name, a deadline and an irreversible cash-out. Here is how these scams work, why they lean on look-alike domains and spoofed display names rather than forging your real domain, and exactly what DMARC, SPF, DKIM and human controls can and cannot do to reduce your exposure.

Read more
5 April 2026 · 11 min read

Homograph and IDN spoofing domains

Homograph and IDN attacks register domains built from confusable Unicode characters that render identically to yours, then authenticate mail from them. Here is why DMARC, SPF and DKIM cannot stop it, how the Punycode trick works, and how to detect, register and monitor the variants that actually matter.

Read more
29 March 2026 · 15 min read

Payroll diversion fraud

Payroll diversion fraud redirects an employee's salary to a criminal's account with a single polite email asking to update bank details. Here is exactly how the direct-deposit redirect scam works over email, which of its four spoofing variants DMARC at enforcement actually stops, and the verification and process controls that close the gaps authentication cannot reach.

Read more
28 March 2026 · 14 min read

QR code phishing (quishing)

Quishing hides a phishing URL inside a QR code so it slips past the URL-aware parts of your mail stack, then teleports the victim onto an unmonitored phone. Here is exactly why filters miss it, where DMARC at p=reject stops the impersonation route and where authentication categorically cannot help, plus the layered technical and user defences that actually work.

Read more
18 March 2026 · 13 min read

Subdomain takeover and email

When a forgotten CNAME or lapsed NS record dangles, an attacker can claim the subdomain, publish their own SPF and DKIM, and send mail that passes SPF, DKIM and DMARC from a real subdomain of your domain. Here is why p=reject does not catch it, how it hides in your reports, and how to find and close dangling DNS before it is exploited.

Read more
17 March 2026 · 14 min read

Thread hijacking email attacks

Thread hijacking inserts a malicious reply into a real conversation you already trust. Here is how attackers obtain the thread, the two delivery techniques that decide whether authentication can stop it, and the layered defences that cover the gaps DMARC cannot.

Read more
16 March 2026 · 12 min read

Typosquatting and email fraud

Attackers register misspelt look-alike domains, authenticate them properly, and send mail that passes every check you have. Here is why your DMARC at p=reject cannot stop ASCII typosquatting, how it differs from homograph spoofing and display-name fraud, and the monitoring, defensive-registration and process layers that actually reduce the risk.

Read more
15 March 2026 · 12 min read

Vendor email compromise

A supplier breach turns into a fraudulent invoice from a genuine, fully authenticated address. Here is how vendor email compromise works, why DMARC passes it cleanly, and the layered controls that actually catch it.

Read more