DMARC Engine
Home/Glossary/Phishing
Glossary

Phishing

Fraudulent messages that impersonate a trusted sender to trick recipients into revealing data or making payments.

Phishing is a social-engineering attack in which a fraudulent message impersonates a trusted organisation or person to trick the recipient into handing over credentials, payment details or money, or into installing malware. Email is the most common channel, though the same tactics appear over SMS and messaging apps.

Most email phishing relies on some form of spoofing. An attacker may forge your exact domain in the From header, register a lookalike domain, or use display-name spoofing so a familiar name appears while the real address is hidden. Targeted variants include spear phishing against named individuals and business email compromise, which often carries no malicious link at all, only a convincing request.

No single control stops every phishing message, but authentication removes the most damaging variant. With DMARC at an enforcement policy of quarantine or reject, messages forging your domain are blocked, so criminals cannot abuse your brand against your customers and staff. Combine that with user awareness, link inspection and a verified BIMI logo that only appears on authenticated mail. To gauge exposure, check whether your domain enforces DMARC rather than sitting at p=none.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.