Tagged “spoofing”
16 articles
Display-name spoofing and why DMARC misses it
Friendly-from spoofing impersonates a person using a domain the attacker legitimately controls, so it passes DMARC every time by design. Here is why DMARC cannot catch it, where it shows up in BEC and CEO fraud, and the layered controls that actually mitigate it.
Read more
Why your domain can be spoofed, and how to stop it
If you own a domain and have never published a DMARC record, anyone on the internet can send email that appears to come from you.
Read more
How invoice fraud begins with a spoofed domain
Invoice fraud usually starts with a forged sender address. Here is how exact-domain spoofing works, what DMARC at p=reject stops, and what it does not.
Read more
Dangling DNS records as an email risk
Stale CNAMEs, SPF includes and DKIM selectors that point to resources you no longer own quietly delegate your sending authority to whoever claims them next. Here is how dangling DNS becomes a real spoofing and SPF risk, and how to find and close the gaps.
Read more
Subdomain policy: the DMARC sp tag
An enforced root domain at p=reject protects exactly one address and can leave every subdomain spoofable. Here is what the DMARC sp tag does, the inheritance trap that catches teams mid-migration, and how to close the gap safely without bouncing legitimate subdomain mail.
Read more
How email spoofing actually works
Email spoofing takes no password and no exploit: SMTP simply trusts whatever the sender types into the From field. This guide traces the mechanism from the raw SMTP conversation, through the crucial split between the envelope-from used for delivery and the header-from a human reads, to the three layered controls (SPF, DKIM and DMARC alignment) that finally make forging your domain fail.
Read more
What is SPF and how does it work?
SPF lets you publish, in DNS, the list of servers allowed to send mail for your domain. Here is how the syntax works, what the all qualifier and each mechanism mean, what SPF actually authorises, the ten-lookup limit that catches everyone, and the spoofing gap that DMARC alignment closes.
Read more
Executive impersonation and CEO fraud
CEO fraud forges your leaders to authorise urgent payments. Enforced DMARC kills exact-domain spoofing outright, but leaves real gaps. Here is exactly what it stops, what it cannot, and the layers you need around it.
Read more
Gift card scams over email
Gift card BEC is business email compromise stripped to its cheapest form: no payload, just a name, a deadline and an irreversible cash-out. Here is how these scams work, why they lean on look-alike domains and spoofed display names rather than forging your real domain, and exactly what DMARC, SPF, DKIM and human controls can and cannot do to reduce your exposure.
Read more
Homograph and IDN spoofing domains
Homograph and IDN attacks register domains built from confusable Unicode characters that render identically to yours, then authenticate mail from them. Here is why DMARC, SPF and DKIM cannot stop it, how the Punycode trick works, and how to detect, register and monitor the variants that actually matter.
Read more
Payroll diversion fraud
Payroll diversion fraud redirects an employee's salary to a criminal's account with a single polite email asking to update bank details. Here is exactly how the direct-deposit redirect scam works over email, which of its four spoofing variants DMARC at enforcement actually stops, and the verification and process controls that close the gaps authentication cannot reach.
Read more
QR code phishing (quishing)
Quishing hides a phishing URL inside a QR code so it slips past the URL-aware parts of your mail stack, then teleports the victim onto an unmonitored phone. Here is exactly why filters miss it, where DMARC at p=reject stops the impersonation route and where authentication categorically cannot help, plus the layered technical and user defences that actually work.
Read more
Subdomain takeover and email
When a forgotten CNAME or lapsed NS record dangles, an attacker can claim the subdomain, publish their own SPF and DKIM, and send mail that passes SPF, DKIM and DMARC from a real subdomain of your domain. Here is why p=reject does not catch it, how it hides in your reports, and how to find and close dangling DNS before it is exploited.
Read more
Thread hijacking email attacks
Thread hijacking inserts a malicious reply into a real conversation you already trust. Here is how attackers obtain the thread, the two delivery techniques that decide whether authentication can stop it, and the layered defences that cover the gaps DMARC cannot.
Read more
Typosquatting and email fraud
Attackers register misspelt look-alike domains, authenticate them properly, and send mail that passes every check you have. Here is why your DMARC at p=reject cannot stop ASCII typosquatting, how it differs from homograph spoofing and display-name fraud, and the monitoring, defensive-registration and process layers that actually reduce the risk.
Read more
Vendor email compromise
A supplier breach turns into a fraudulent invoice from a genuine, fully authenticated address. Here is how vendor email compromise works, why DMARC passes it cleanly, and the layered controls that actually catch it.
Read more