Attack types
What is email spoofing?
Forging the sender name or address on an email so it appears to come from someone the recipient trusts.
In more detail
Spoofing ranges from changing only the display name, to registering a lookalike domain, to forging the exact address of a domain that has not published a strict DMARC policy. It is a delivery method rather than an attack on its own: most spoofed email is phishing, business email compromise or invoice fraud.
Why it matters
The name in the From line is the least reliable thing in an email. A habit of checking the full address, and of confirming unusual requests another way, holds up even when the forgery is perfect.
Related terms
An attack that impersonates a trusted person — usually an executive or a supplier — to trigger a payment or a data transfer.
A pre-built simulated phishing email that mimics a specific attack type, such as credential harvesting, business email compromise or brand impersonation.
Phishing delivered over SMS text messages.
Vocabulary is the easy part. Behavior is the job.
Thirty minutes, a live account, and a straight answer about where your people actually stand.