Email security glossary

Plain-English explanations of the terms behind email fraud, grouped by theme and written for people running a business, not a security team. Open any term to read the full explanation.

Attack types

Phishing A message designed to trick you into a harmful action.

Phishing is a scam message designed to trick you into doing something harmful: clicking a malicious link, entering your password on a fake login page, opening a booby-trapped attachment, or paying money to a criminal. It usually pretends to be from someone you trust, such as your bank, a supplier, a colleague, or a delivery company, and it pushes you to act quickly, before you stop to check.

Spear phishing Phishing aimed at one specific person or business.

Spear phishing is phishing tailored to a specific target rather than sent in bulk. The attacker researches the person or business first, then references real names, real projects, or a genuine supplier to make the message far more convincing. Because it looks personal and informed, it slips past both filters and instinct more easily than a generic scam.

Whaling Spear phishing that targets senior executives.

Whaling is spear phishing aimed at the most senior people in an organisation, such as a chief executive or finance director. The goal is usually a large payment or access to sensitive information, using the authority of a top role to pressure staff into acting without question. A single successful whaling attack can be very costly, which is why these individuals are singled out.

Business Email Compromise (BEC) Targeted email fraud using trust, often with no link at all.

BEC is targeted email fraud aimed at organisations. A criminal impersonates a senior person, a supplier, or a trusted contact, sometimes after breaking into a real mailbox, and uses that trust to request an urgent payment, a change of bank details, or sensitive information. There is often no link or attachment at all, which is why it slips past filters that only look for those. It relies on human trust, not malware.

Invoice fraud and payment diversion Tricking a business into paying a criminal, not a supplier.

Invoice fraud tricks a business into paying money to a criminal instead of a genuine supplier. It often arrives as a convincing email, sometimes from a compromised real account, asking to update the bank details on file, or attaching a fake invoice. The change looks routine, which is exactly why it works. Always verify a change of bank details through a channel other than the email that requested it.

Clone phishing A copy of a real email you received, with the links swapped.

Clone phishing takes a genuine email you have already received, copies it almost exactly, and resends it with the links or attachments replaced by malicious ones. Because the message matches something real, often with a plausible excuse such as resending a corrected file, it is unusually convincing. The tell is that a message you thought was already dealt with suddenly reappears.

QR code phishing (quishing) A malicious link hidden inside a QR code.

Quishing hides a malicious link inside a QR code, often in an email or on a printed notice, so it bypasses link-scanning tools and lands on a personal phone that may be less protected. The code leads to a fake login page or a malware download. Treat an unexpected QR code with the same caution as an unexpected link.

Smishing and vishing Phishing by text message (smishing) or phone call (vishing).

Smishing is phishing delivered by text message, and vishing is phishing delivered by a phone call. Both use the same playbook as email phishing, impersonating a trusted organisation and creating urgency, but they move to channels people trust more and question less. A common pattern combines them with email, such as a text claiming to be your bank followed by a call to confirm the details you just gave up.

Email authentication and spoofing

Email spoofing Faking the sender address so a message looks like someone else.

Spoofing is faking the "from" address on an email so it appears to come from someone it does not. Plain email was never built to prove who sent it, so on its own the sender name and address can be forged. The modern checks below (SPF, DKIM and DMARC) exist to catch this, which is why a domain without them is easier to impersonate.

Display name spoofing A trusted-looking name hiding a completely different address.

Display name spoofing sets the friendly sender name to someone you trust, such as "Sarah, Finance", while the actual email address behind it belongs to the attacker. Many mail apps, especially on phones, show only the display name, so the fake looks genuine at a glance. Tapping or hovering to reveal the real address is the quickest way to catch it.

Lookalike domain and homoglyph A domain deliberately made to resemble a real one.

A lookalike domain is one deliberately registered to resemble a real one, so an email or link from it looks legitimate at a glance. Tactics include swapping letters (rn for m), using a different ending (.co instead of .com), inserting words (acme-payments.com), or using lookalike characters from other alphabets. That last trick is a homoglyph, where a Latin letter is replaced by a nearly identical one from another script.

Cousin domain A believable but different domain, such as adding a word.

A cousin domain is a close relative of a real domain that is plausible rather than a near-copy, such as acme-billing.com or acmesupport.net alongside the genuine acme.com. It does not rely on hard-to-spot character tricks. It relies on looking reasonable enough that nobody questions it. These are cheap to register and are a staple of invoice fraud.

SPF (Sender Policy Framework) A published list of who may send email for a domain.

SPF is a public list, published in a domain's DNS records, of which mail servers are allowed to send email for that domain. When a message arrives, the receiving server can check whether it came from an approved server. A pass is a good sign. A fail suggests the sender may be forged.

DKIM (DomainKeys Identified Mail) A cryptographic signature proving an email was not altered.

DKIM adds a cryptographic signature to each email that proves the message genuinely came from the domain it claims, and was not altered in transit. The receiving server checks the signature against a public key in the domain's DNS. A valid DKIM signature is strong evidence the email is authentic.

DMARC The policy that ties SPF and DKIM together and enforces them.

DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails both: allow it, quarantine it, or reject it. A domain with a strict DMARC policy is much harder to impersonate. A domain with no DMARC, or a policy of "none", offers no enforcement, so anyone can send email that appears to come from it.

How attacks reach you

Malicious attachment A file that runs harmful code when opened.

A malicious attachment is a file that carries harmful code, disguised as an invoice, a receipt, a CV, or a shipping notice. Opening it, or enabling its content, can install malware or hand over control of your device. Unexpected attachments deserve suspicion even when the sender looks familiar, because a real account can be compromised.

Macro Automated commands inside a document that can be abused.

A macro is a small set of automated commands built into a document such as a spreadsheet or word processor file. Macros have legitimate uses, but attackers hide harmful instructions inside them, then design the email to talk you into clicking "enable content". A document that demands you enable macros before you can read it is a classic warning sign.

Credential harvesting Fake login pages built to steal your username and password.

Credential harvesting is the theft of usernames and passwords, usually through a fake login page that mimics a service you use. You follow a link, see a familiar sign-in screen, and type your details straight to the attacker. Stolen credentials are then used directly, sold on, or used to launch further attacks from inside a real account.

Payload The harmful part of an attack that does the damage.

The payload is the part of an attack that actually causes harm once a victim takes the bait: the malware that installs, the page that steals a password, or the script that runs. Everything else, the convincing email and the disguised link, exists only to deliver it. Blocking delivery is why filtering links and attachments matters so much.

Drive-by download Malware that installs just from visiting a web page.

A drive-by download installs malware simply because you visited a web page, with no need to click anything or agree to a download. It works by exploiting a flaw in an outdated browser or plugin. Keeping software updated closes most of these gaps, which is one reason update prompts are worth acting on quickly.

Reply-to abuse A message that quietly routes your reply to the attacker.

Reply-to abuse sets the hidden reply-to address to the attacker while the visible sender still looks genuine. The message may even pass basic checks, but the moment you reply, your response goes to the criminal rather than the real contact. It is common in invoice fraud, where a natural exchange of replies is used to steer a payment.

The bigger picture

Social engineering Manipulating people, rather than machines, into a mistake.

Social engineering is the art of manipulating people into giving up information or taking an unsafe action, rather than breaking through technology. It leans on trust, authority, urgency, fear, and helpfulness. Almost every email scam is social engineering at its core, which is why awareness matters as much as any filter.

Malware Any software written to harm or take control of a device.

Malware is a general term for any software written to damage, disrupt, or take control of a device, including viruses, spyware, and trojans. Email is one of the most common ways it spreads, hidden in attachments or behind links. Once installed, it can steal data, watch what you type, or open a door for further attacks.

Ransomware Malware that locks your files and demands payment.

Ransomware is malware that encrypts your files, or entire systems, then demands a payment to unlock them. It often enters through a phishing email or a malicious attachment, then spreads across a network. Reliable, tested backups are the single most effective defence, because they let you recover without paying a criminal.

Account takeover A criminal gaining control of a real, trusted mailbox.

Account takeover is when a criminal gains control of a legitimate email account, usually through a stolen or guessed password. From inside a real, trusted mailbox they can read past conversations and send convincing fraud to that person's genuine contacts. That is why these emails are so effective: they come from a real address, with real context.

Pretexting Inventing a believable story to justify the request.

Pretexting is the invented backstory that makes a scam feel legitimate, such as a supplier explaining that their bank has changed, or IT support needing to verify your login for an upgrade. The story lowers your guard and gives the harmful request a reasonable-sounding excuse. A request that arrives wrapped in an unusually detailed justification is worth a second look.

Insider threat Risk that comes from someone inside the organisation.

An insider threat is a risk that comes from within: a current or former employee, contractor, or partner who misuses their access, whether deliberately or by accident. In an email context, this includes someone forwarding sensitive information out, or falling for a scam that hands their access to an outsider. Limiting access to what each role actually needs reduces the damage either way.

Supply chain attack Reaching you through a supplier or partner you trust.

A supply chain attack reaches a target indirectly, through a trusted supplier, partner, or piece of software rather than head on. In email, this often means a genuine supplier's account is compromised and then used to attack their customers, who have every reason to trust the sender. It is powerful precisely because the trust between the two businesses is real.

Defence and response

Threat intelligence Shared knowledge about active threats, used to spot them faster.

Threat intelligence is collected, shared knowledge about active threats: the domains, senders, and patterns behind current attacks. Pooled across many organisations, it lets everyone recognise a scam that others have already reported, often before it reaches them. This shared, network effect is the whole idea behind Sender Registry.

Indicator of compromise (IOC) A concrete clue that an attack has happened or is underway.

An indicator of compromise, or IOC, is a specific, concrete clue that an attack has occurred or is in progress, such as a malicious domain, a sender address, a file, or a suspicious link. IOCs are what make intelligence actionable: once one is known, it can be searched for, watched, and blocked elsewhere. Much of what Sender Registry records is, in effect, a growing catalogue of IOCs.

Sandboxing Opening a suspicious file safely in an isolated space.

Sandboxing runs a suspicious file or link inside an isolated, disposable environment to see what it does, safely away from real systems. If it tries to install malware or steal data, that behaviour is caught without any real harm. It is a way to judge something by its actions rather than its appearance.

Quarantine Holding a suspect message aside instead of delivering it.

To quarantine a message is to hold it aside rather than deliver it straight to the inbox, so it can be reviewed before anyone acts on it. This gives a safety margin for anything that looks risky but is not certainly malicious. A quarantined message can then be released if genuine, or discarded if confirmed as a threat.

Multi-factor authentication (MFA) A second proof of identity beyond just a password.

Multi-factor authentication, or MFA, requires a second proof of identity in addition to your password, such as a code from an app or a tap on your phone. Because a stolen password alone is then not enough to get in, MFA is one of the most effective defences against account takeover. Turning it on for email is one of the highest-value security steps a small business can take.

Zero trust Verify everything, trust nothing automatically.

Zero trust is a security approach that assumes no user, device, or request should be trusted automatically, even inside your own network. Instead of trusting anything by default, each access is verified on its own merits. In everyday terms it echoes the core email habit: verify an unexpected request through a separate channel before acting, rather than trusting it because it looks familiar.

Wondering about a specific domain, sender or link? Check what the network knows.