DMARC Engine
Home/Blog/Tagged “lookalike-domains”
Blog

Tagged “lookalike-domains”

8 articles

3 June 2026 · 12 min read

How invoice fraud begins with a spoofed domain

Invoice fraud usually starts with a forged sender address. Here is how exact-domain spoofing works, what DMARC at p=reject stops, and what it does not.

Read more
3 June 2026 · 16 min read

Dangling DNS records as an email risk

Stale CNAMEs, SPF includes and DKIM selectors that point to resources you no longer own quietly delegate your sending authority to whoever claims them next. Here is how dangling DNS becomes a real spoofing and SPF risk, and how to find and close the gaps.

Read more
31 May 2026 · 11 min read

How email spoofing actually works

Email spoofing takes no password and no exploit: SMTP simply trusts whatever the sender types into the From field. This guide traces the mechanism from the raw SMTP conversation, through the crucial split between the envelope-from used for delivery and the header-from a human reads, to the three layered controls (SPF, DKIM and DMARC alignment) that finally make forging your domain fail.

Read more
25 May 2026 · 11 min read

Lookalike and cousin domains

Attackers register confusable domains that authenticate perfectly and slip past your defences, because your DMARC policy protects only the exact name it is published under. Here is how homoglyph and cousin domains work, the precise reason a p=reject policy cannot touch them, and the layered plan that actually defends your brand.

Read more
14 May 2026 · 13 min read

Email authentication for financial services

For banks, insurers and fintechs, DMARC, SPF, DKIM, MTA-STS and BIMI are anti-fraud and brand-protection controls, not deliverability tweaks. How to meet regulatory expectations and reach p=reject across a multi-vendor estate without breaking OTP or statement mail.

Read more
11 May 2026 · 14 min read

Email authentication for healthcare and HIPAA

HIPAA never names DMARC, but it asks for exactly what SPF, DKIM and DMARC deliver: protection of transmitted PHI, integrity, sender authentication and ongoing risk management. Here is how email authentication maps onto the HIPAA Security Rule, why DMARC reporting need not expose PHI, and the staged path to p=reject that does not break clinical email.

Read more
7 May 2026 · 11 min read

Email authentication for law firms

How solicitors use SPF, DKIM and DMARC to stop their domain being spoofed, protect client money on completions, and meet their confidentiality duties, with a staged, no-outage path to p=reject.

Read more
2 May 2026 · 14 min read

Email authentication for nonprofits

For charities, DMARC is donor trust and fundraising revenue expressed as DNS records: it stops attackers spoofing your appeals and lifts your own appeals out of the spam folder. Here is how to align every sender, ramp safely to p=reject, and put your logo in the inbox, including via a Common Mark Certificate when your charity logo is not a registered trademark.

Read more