Phishing is a social-engineering attack in which a fraudulent message impersonates a trusted organisation or person to trick the recipient into handing over credentials, payment details or money, or into installing malware. Email is the most common channel, though the same tactics appear over SMS and messaging apps.
Most email phishing relies on some form of spoofing. An attacker may forge your exact domain in the From header, register a lookalike domain, or use display-name spoofing so a familiar name appears while the real address is hidden. Targeted variants include spear phishing against named individuals and business email compromise, which often carries no malicious link at all, only a convincing request.
No single control stops every phishing message, but authentication removes the most damaging variant. With DMARC at an enforcement policy of quarantine or reject, messages forging your domain are blocked, so criminals cannot abuse your brand against your customers and staff. Combine that with user awareness, link inspection and a verified BIMI logo that only appears on authenticated mail. To gauge exposure, check whether your domain enforces DMARC rather than sitting at p=none.
Check it on your domain
- DMARC Checker: looks up and validates a domain's DMARC record and policy.
- Phishing Email Checker: analyses a suspicious email's headers and content.