Browse the Learning Center
Email threats
Phishing, BEC, spoofing, and the wider security landscape.
111 guides
All Email threats guides
Email sender spoof: how to spot and stop itAn email sender spoof forges a trusted domain in the visible From field. Spot one in the receiver's authentication results; DMARC limits it on your own domain.
Pixm phishing protectionPixm phishing protection is browser-layer protection that Pixm says uses AI computer vision to stop credential phishing from email, SMS, LinkedIn, and.
What is an anti-phishing program?Anti phishing program: an operating model for ownership, controls, reporting, response, and measurement that reduces organizational phishing risk.
Anti-phishing software: how to compare business toolsAnti phishing software comparison for businesses: evaluate native controls, dedicated email security, DMARC, and sender-domain protection options.
Business email compromise is financially motivatedBusiness email compromise attacks are financially motivated scams that seek unauthorized fund transfers, not typically disruption-motivated attacks or.
Is business email compromise the most expensive cyberattack?Business email compromise ranks second by total losses in the FBI's 2025 figures, behind investment fraud, but leads every category on loss per complaint.
Can email addresses be spoofed?Can email addresses be spoofed? Yes. Learn how displayed From addresses can be forged, how DMARC helps, and how to check a suspicious email.
Email security testing tools: run, interpret, repair, retestEmail security testing tools help safely test gateway handling of safe threats, interpret blocking or disarming results, repair gaps, and retest.
Email spoofing in cyber securityEmail spoofing in cyber security is the use of a forged email identity to make a message appear to come from a trusted sender and domain.
ESET anti-phishing protection is non-functionalESET anti-phishing protection is non-functional when its product-specific status needs diagnosis. Identify the product, symptom, and official support path.
Gmail phishing protectionGmail phishing protection combines Gmail warnings with careful verification and reporting. Learn what to check before you click or respond today.
How to block spoofed emailsHow to block spoofed emails: use separate inbound email-security controls and domain-authorization controls instead of relying on one blocked message.
Norton phishing protection: what Scam Protection confirmsNorton phishing protection includes advertised Scam Protection on selected plans, but Norton does not document phishing-email coverage or guarantees.
O365 phishing protectionO365 phishing protection requires current Microsoft documentation for the tenant's licensed controls, policies, reporting options, and validation evidence.
Phishing protection for Office 365Phishing protection Office 365 requires tenant-specific controls, user reporting, and evidence from real messages. Learn what to verify for your tenant.
The goals of email spoofing include luring the user intoThe goals of email spoofing include luring users into sharing credentials, financial details, or visiting malicious sites through a trusted-looking.
ThreatDown browser phishing protectionThreatDown browser phishing protection is listed in its pre-delivery layer. See how it differs from email security and DNS filtering for domain owners.
What is URL spoofing and how can I stop it?URL spoofing uses deceptive web addresses to send people to attacker-controlled sites. Learn how to inspect links and reduce phishing risk safely.
What is quishing (QR code phishing) and how do you stop it?Quishing is QR code phishing that hides a malicious link in a scannable image. Learn how to identify it and reduce the risk of credential theft.
AI powered email security: what the label actually coversAI powered email security covers content and behavior models, not domain authentication. See what vendors document, and how to test any AI claim.
Cisco advanced phishing protectionUnderstand Cisco Advanced Phishing Protection, its gateway sensor flow, current support limits, and the tenant evidence needed to verify coverage.
Email security for small business: what actually matters firstThe working order for small business email security: MFA first, then the controls Microsoft 365 and Google Workspace already include, then DMARC.
Protect your brand from impersonation with anti-spoofingProtect your brand from impersonation with anti-spoofing by aligning SPF and DKIM, enforcing DMARC carefully, and recording response evidence.
How does IP spoofing work and how can you stop it?IP spoofing works by forging a packet's source address. Learn how ingress filtering, source validation, and authentication reduce its impact.
Pharming vs phishingPharming vs phishing: phishing uses a deceptive lure, while pharming redirects users to a fraudulent site through technical means. Learn the difference.
Phishing protection browser add onSet up a phishing protection browser add on safely, review permissions, validate the control, and keep a rollback path.
What is angler phishing and how can you stop it?Angler phishing uses fake social-media support accounts to exploit public complaints. Learn how to verify support and limit email impersonation.
What is phone number spoofing and how do you stop it?Phone number spoofing falsifies caller ID. Learn how spoofed calls work, how to respond safely, and what carrier authentication can do today.
Business Email Compromise (BEC) attacks: 2025 guideBusiness Email Compromise (BEC) attacks impersonate trusted people or vendors to redirect money or data. Learn the warning signs and controls.
Why is phishing so effective?Phishing works by pairing trusted-looking context with pressure and a simple requested action. Learn how to interrupt the decision safely.
Best email security: 8 options comparedBest email security: 8 options checked on deployment model, threats named and published pricing, from first-party vendor pages read on 12 August 2026.
Email security software: how to choose a category fitEmail security software covers four types: secure email gateways, API-connected tools, native provider controls, and the DMARC layer. Find your fit.
Mimecast email security: what it does and what it cannot proveMimecast email security is a vendor email-security offering, but its name alone cannot prove a specific email is safe, encrypted, or legitimate.
Phishing attack protection: the controls that actually workPhishing attack protection combines phishing-resistant MFA, DMARC enforcement, user training, and reporting; no single control stops every attempt.
Phishing scam email example: how to assess one safelyPhishing scam email examples reveal sender, urgency, and link clues. Learn how to inspect a suspicious email and verify it safely for safer decisions.
What is an impersonation attack and how can you stop it?An impersonation attack poses as a trusted person or domain to obtain money, data, or access. Learn how to identify, contain, and reduce email.
Advanced Email Security from GoDaddyAdvanced Email Security from GoDaddy is a Microsoft 365 email protection service with spam, phishing, quarantine, and encryption controls for tenants.
Amazon report phishing emailAmazon report phishing email: do not use message links. Verify the issue independently, then forward suspicious Amazon mail to Amazon's official route.
Cloud based email securityCloud based email security adds a cloud-delivered protection layer around cloud mailboxes. Assess the controls included before selecting a service.
Email security Proofpoint: what Core Email Protection coversEmail security Proofpoint refers to Proofpoint's Core Email Protection, with API and secure email gateway options. Learn what evidence to request.
Email security protocolsEmail security protocols protect different parts of email: transport, mailbox access, and domain authentication. See how TLS, SMTP, SPF, DKIM, and DMARC.
How to move from reactive to proactive email securityHow to move from reactive to proactive email security: establish an authenticated sending baseline, validate real mail, and review change evidence.
How to keep email authentication strong through multiple acquisitionsEmail authentication stays strong through acquisitions when teams inventory domains and senders, assign ownership, validate mail, and phase DMARC.
Paypal phishing scam emailPaypal phishing scam emails should be verified outside the message. Learn how to separate an impostor email from an unfamiliar PayPal request.
Report email phishing scamsReport email phishing scams through a verified provider or organization process. Use this decision rule when the correct reporting route is unknown.
Report a Social Security phishing emailReport a Social Security phishing email safely: do not reply, pay, or share information. Verify any reporting destination is an official government site.
What are the 3 types of email impersonation attacks?Email impersonation attacks commonly use an exact domain, a lookalike domain, or a free-mail account. Learn how each type works. Learn what to verify.
What are the top email security tips for small businesses?Email security tips for small businesses: use MFA, verify sensitive requests, authenticate sending domains, and test recovery paths safely today.
What exactly is spoofing and how can you stop it?Spoofing is impersonation that makes a message, call, website, or network request appear trusted. Learn how to identify and limit spoofing for your domain.
What is email spoofing and how can you prevent it?Email spoofing forges sender details to make mail look trusted. Stop spoof emails with SPF, DKIM, DMARC enforcement, header checks, and user reporting.
What is a whaling attack and how can you stop it?What is a whaling attack? It is targeted phishing aimed at senior leaders. Learn how to verify requests and reduce email impersonation risk.
What is whaling phishing and how can you prevent it?Whaling phishing is a targeted impersonation attack against executives or people who can approve payments. Learn how to verify and reduce the risk.
Amazon phishing scam emailAmazon phishing scam emails should be treated as untrusted: do not use their links, verify the claim in Amazon directly, then report the message.
What is an email security gateway?An email security gateway inspects mail before it reaches recipients. It runs in front of the mailbox, alongside it through an API, or built into the platform.
Phishing-resistant MFA: does it stop device code phishing?Phishing-resistant MFA (FIDO2/WebAuthn, PKI) blocks proxy phishing by binding to a site's origin — but it does not stop device code phishing. Here's why.
Business email compromise vs phishingBusiness email compromise vs phishing: classify a suspicious request by its identity and payment or access objective before acting, using the message.
How to enable phishing and malware protection in Google WorkspaceEnable phishing and malware protection in Google Workspace by configuring Gmail Safety controls, actions, organizational units, and message checks.
Spam vs phishingSpam vs phishing: spam is unsolicited bulk email, while phishing uses deception to steal information or prompt harmful action from recipients.
What is a browser-in-the-browser attack?A browser-in-the-browser (BitB) attack fakes a login popup with a forged address bar to steal credentials. Here's how it works and how to spot and stop it.
Abnormal email securityAbnormal email security is an API-connected cloud email-security offering. Compare its buyer evidence with gateway and DMARC boundaries in practice.
Avanan email securityAvanan email security is Check Point API-based email protection. Compare its documented scope with sender authentication and deployment needs.
Barracuda email securityBarracuda email security: compare Barracuda Email Protection with Palisade by deployment scope, DMARC workflow, buyer fit, and DMARC evidence.
Sublime email securityUnderstand Sublime email security's documented scope, what it does not prove in a tenant, and how to evaluate it alongside sender-domain authentication.
Zix email security: what the name means todayZix email security now sits within OpenText Cybersecurity. Learn what its encryption service does and where SPF, DKIM, and DMARC differ today.
What is ping spoofing and does it matter?Ping spoofing means faking your network latency — a PvP game cheat, and separately an ICMP source-address trick. Here is what each one is and when it matters.
What is a quid pro quo attack?A quid pro quo attack trades a fake favour — IT help, a gift, a job — for your credentials or access. Here is how it works and how to stop it.
What is piggybacking in cybersecurity?Piggybacking in cybersecurity is when an authorized person knowingly lets an unauthorized one into a restricted area — how it differs from tailgating.
Is Have I Been Pwned safe to use?Have I Been Pwned is safe to use: it never logs your searches, and the password checker uses k-anonymity so your password never leaves your device.
What is a honeytrap scam and how do you spot one?A honeytrap scam uses a fake romantic or friendly connection to manipulate a target into sending money or leaking data. Learn how to spot one.
What is pharming and how do you prevent it?Pharming redirects you to fake websites by corrupting DNS or your hosts file to steal logins. Learn how pharming works and how to prevent it.
Why am I getting fake law enforcement emails?Fake law enforcement emails are a phishing scam: a July 2026 campaign impersonates Interpol to push ransomware at small businesses. How to spot and stop them.
Spoofing vs phishing: what's the difference?Spoofing vs phishing: spoofing fakes an identity, while phishing uses deception to prompt a harmful action. Learn how email authentication fits.
What are rogue apps and how can I stop them?Rogue apps are malicious OAuth apps that bypass MFA via consent phishing. How MSPs detect, remove, and prevent illicit consent grants in Microsoft 365 and
How does dark web activity threaten organizations?Dark web markets sell stolen credentials that fuel ransomware and BEC. How the trade works, what monitoring can and can't do, and how MSPs should respond.
How does sandboxing help stop malware?FAQ: sandboxing basics, how it works, benefits, and where to use it in security stacks.
How fast should your team respond to incidents (MTTR)?A concise guide to Mean Time to Respond (MTTR) in cybersecurity: definition, calculation, and tactics to lower response times.
How does malspam work — and how can organizations stop it?Learn what malspam is, how it operates, and clear defensive steps IT teams can use to stop it.
Why should organizations run regular phishing simulations?Why perform routine phishing simulations, the best practices, and quick steps to strengthen employee detection and reporting.
Can Rockstar 2FA bypass Microsoft 365 MFA?Rockstar 2FA is a phishing-as-a-service kit that steals M365 session cookies to bypass MFA. How the AiTM attack works and what actually stops it.
Is November’s shopping frenzy the prime time for cyber scams?November shopping spikes cyber scams. Learn the top threats, real examples, and practical steps MSPs and SMBs can take to reduce risk.
Why does healthcare data attract ransomware attackers so often?Why healthcare records draw ransomware attacks and what IT teams can do to reduce risk and recover quickly.
How can healthcare organizations stop ransomware?Practical steps healthcare teams can take to reduce ransomware risk: backups, MFA, training, segmentation, and monitoring.
How long should organizations retain EDR data for investigations?How long to keep EDR data: vendor defaults (14-30 days), what PCI DSS and HIPAA require, and how to size retention to real attacker dwell times.
How can attackers exploit OAuth device code login?How attackers exploit Device Code flow, what risks that creates, and practical mitigations for security teams.
How do you choose the right endpoint security solution?How to choose endpoint security: what EDR must include, how to read MITRE and AV-Comparatives tests, vendor questions for MSPs, and rollout steps.
How could the Israel–Iran cyber war affect U.S. companies?How the Israel–Iran cyber conflict, hacktivism, and AI disinformation create risks for U.S. companies — and what security teams should do now.
How can you simulate fileless credential dumping?Practical Q&A on simulating in-memory credential theft to validate endpoint protections and incident response.
Can attackers use trusted installers to blind EDR?How attackers hide payloads inside legitimate installers to bypass endpoint detection and create blind spots; detection and mitigation steps for IT teams.
How did ShinyHunters use vishing and OAuth abuse to breach the cloud?How social engineering and OAuth token misuse let attackers access cloud CRM data — and what security teams should do now.
How can organizations stop the top identity-related threats?Explore the leading identity threats—BEC, credential stuffing, ATO, auth bypass—and how MSPs can prevent them with MFA, least privilege, MDR, and DMARC.
How is security innovation reshaping managed security services?Explore platform updates: ITDR for Google Workspace beta, phishing simulations at scale, one-click agent uninstall, AI improvements, and recent awards.
How are identity threats evolving against Google Workspace in 2025?Identity attacks on Google Workspace surged in 2025. Learn key trends, defenses, quick takeaways, and FAQs for IT teams.
DoS vs DDoS Attacks: What's the Difference?DoS vs DDoS: a DoS attack floods a target from one source, a DDoS from thousands of botnet devices. Compare scale, tracing, blocking, and defenses.
What are the easiest ways to protect your business data?Learn ten easy data protection solutions, from firewalls to user behavior analysis, to keep your business safe from breaches.
What Are the Five Stages of Penetration Testing?Learn the five stages of penetration testing, from planning to retesting, and why each step is crucial for protecting your business against cyber threats.
Why a single solution can’t stop ransomware?Discover why ransomware evolves, the limits of single defenses, and practical steps to protect your organization with layered security.
What is a computer worm and how does it spread?A computer worm is a self‑replicating piece of malicious software that spreads without needing to attach to a host file.
Why are 97% of Indonesian domains vulnerable to cyberattacks?Recent analysis of Indonesia’s country‑code top‑level domains (ccTLDs) shows a staggering security gap.
What Were the Major Email Security Highlights in September 2021?September 2021 saw a flurry of email‑related security news, ranging from regulatory actions to new protection tools. What regulatory action did the U.S.
What Were the Key Email Security Highlights in October 2021?Cybersecurity Awareness Month, launched by the U.S. Department of Homeland Security, runs every October to promote best practices in digital safety.
Why are targeted email attacks so hard to stop?Targeted email attacks—often called spear‑phishing—are engineered to look like legitimate communication, making them notoriously hard to detect and stop.
Which email security stories mattered in April 2022?Welcome back to our weekly security roundup. This week’s focus is on three major email‑related incidents that could impact your organization’s defenses.
Why must NZ government domains adopt new email standards?New Zealand’s Digital Government has released the Secure Government Email (SGE) Framework, a modern set of technical controls that replace the legacy…
How can AI and zero trust improve email security?Email security isn’t what it used to be. Today’s cybercriminals wield AI to craft phishing emails that can fool even senior executives.
What is TLS? Transport Layer Security ExplainedLearn how TLS protects your data with encryption, authentication, and integrity checks.
What is a Firewall? Network Security Basics ExplainedDiscover what firewalls are, how they work, and why they’re crucial for network security.
What is an email Alias? Uses, Setup and SecurityDiscover what an email alias is and how it organizes your inbox.
What is Spear Phishing? Targeted Attacks ExplainedSpear phishing is a targeted email attack that impersonates someone you trust. Learn how it works, why it succeeds, and how to defend against it.
What is Malware? Types, Examples and PreventionExplore malware, harmful software spread via phishing, and how SPF, DKIM, DMARC protect you.
What is spoofing? Email spoofing attacks explainedSpoofing is impersonation that falsifies an email, IP, or caller identity. Learn how email spoofing works, how to verify it, and what to check.
What is phishing? Attack types and prevention guideWhat is phishing? It is a deceptive message or site that steals data or prompts harmful actions. Learn common attack types and prevention steps.