Tagged “phishing”
12 articles
Dangling DNS records as an email risk
Stale CNAMEs, SPF includes and DKIM selectors that point to resources you no longer own quietly delegate your sending authority to whoever claims them next. Here is how dangling DNS becomes a real spoofing and SPF risk, and how to find and close the gaps.
Read more
PCI DSS 4.0, cyber-insurance and email authentication
PCI DSS 4.0 Requirement 5.4.1 and cyber-insurance questionnaires now treat anti-phishing as a measurable control. Here is exactly how that intersects with DMARC, SPF and DKIM, what counts as evidence, and how to reach enforcement without breaking your own mail.
Read more
Phishing and business email compromise
Business email compromise rarely uses malware: it borrows trust by impersonating people you already deal with. Here is how phishing and BEC work, where the money goes, and the layered defences, with DMARC at enforcement as the load-bearing wall.
Read more
Executive impersonation and CEO fraud
CEO fraud forges your leaders to authorise urgent payments. Enforced DMARC kills exact-domain spoofing outright, but leaves real gaps. Here is exactly what it stops, what it cannot, and the layers you need around it.
Read more
Gift card scams over email
Gift card BEC is business email compromise stripped to its cheapest form: no payload, just a name, a deadline and an irreversible cash-out. Here is how these scams work, why they lean on look-alike domains and spoofed display names rather than forging your real domain, and exactly what DMARC, SPF, DKIM and human controls can and cannot do to reduce your exposure.
Read more
Homograph and IDN spoofing domains
Homograph and IDN attacks register domains built from confusable Unicode characters that render identically to yours, then authenticate mail from them. Here is why DMARC, SPF and DKIM cannot stop it, how the Punycode trick works, and how to detect, register and monitor the variants that actually matter.
Read more
Payroll diversion fraud
Payroll diversion fraud redirects an employee's salary to a criminal's account with a single polite email asking to update bank details. Here is exactly how the direct-deposit redirect scam works over email, which of its four spoofing variants DMARC at enforcement actually stops, and the verification and process controls that close the gaps authentication cannot reach.
Read more
QR code phishing (quishing)
Quishing hides a phishing URL inside a QR code so it slips past the URL-aware parts of your mail stack, then teleports the victim onto an unmonitored phone. Here is exactly why filters miss it, where DMARC at p=reject stops the impersonation route and where authentication categorically cannot help, plus the layered technical and user defences that actually work.
Read more
Subdomain takeover and email
When a forgotten CNAME or lapsed NS record dangles, an attacker can claim the subdomain, publish their own SPF and DKIM, and send mail that passes SPF, DKIM and DMARC from a real subdomain of your domain. Here is why p=reject does not catch it, how it hides in your reports, and how to find and close dangling DNS before it is exploited.
Read more
Thread hijacking email attacks
Thread hijacking inserts a malicious reply into a real conversation you already trust. Here is how attackers obtain the thread, the two delivery techniques that decide whether authentication can stop it, and the layered defences that cover the gaps DMARC cannot.
Read more
Typosquatting and email fraud
Attackers register misspelt look-alike domains, authenticate them properly, and send mail that passes every check you have. Here is why your DMARC at p=reject cannot stop ASCII typosquatting, how it differs from homograph spoofing and display-name fraud, and the monitoring, defensive-registration and process layers that actually reduce the risk.
Read more
Vendor email compromise
A supplier breach turns into a fraudulent invoice from a genuine, fully authenticated address. Here is how vendor email compromise works, why DMARC passes it cleanly, and the layered controls that actually catch it.
Read more