DMARC Engine
Home/Glossary/Display-name spoofing
Glossary

Display-name spoofing

A scam where the sender's friendly display name is forged to look trusted, even though the real email address is unrelated.

Display-name spoofing is a form of impersonation that abuses the friendly name shown beside an email address. An address is written as Finance Team <attacker@gmail.com>, but many mail clients, especially on mobile, show only the display name. The recipient sees a trusted name and never notices the underlying address is unrelated.

It matters because it is cheap, effective and often the opening move in business email compromise and phishing. The attacker does not need to control your domain at all, which is what makes this attack distinct from outright domain forgery.

This is also why DMARC does not stop it on its own. DMARC validates the domain in the From header against SPF and DKIM; if the message is sent from a domain the attacker legitimately controls, it can pass authentication while still carrying a deceptive display name.

Defending against it combines layers: enforce DMARC so your real domain cannot be forged, train staff to inspect the full address rather than the name, and adopt BIMI so verified senders show a trusted logo that imposters cannot replicate. Watch too for the related trick of lookalike domains in the address itself.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.