Plain-English explanations of the terms behind email fraud, grouped by theme and written for people running a business, not a security team. Open any term to read the full explanation.
Phishing is a scam message designed to trick you into doing something harmful: clicking a malicious link, entering your password on a fake login page, opening a booby-trapped attachment, or paying money to a criminal. It usually pretends to be from someone you trust, such as your bank, a supplier, a colleague, or a delivery company, and it pushes you to act quickly, before you stop to check.
Spear phishing is phishing tailored to a specific target rather than sent in bulk. The attacker researches the person or business first, then references real names, real projects, or a genuine supplier to make the message far more convincing. Because it looks personal and informed, it slips past both filters and instinct more easily than a generic scam.
Whaling is spear phishing aimed at the most senior people in an organisation, such as a chief executive or finance director. The goal is usually a large payment or access to sensitive information, using the authority of a top role to pressure staff into acting without question. A single successful whaling attack can be very costly, which is why these individuals are singled out.
BEC is targeted email fraud aimed at organisations. A criminal impersonates a senior person, a supplier, or a trusted contact, sometimes after breaking into a real mailbox, and uses that trust to request an urgent payment, a change of bank details, or sensitive information. There is often no link or attachment at all, which is why it slips past filters that only look for those. It relies on human trust, not malware.
Invoice fraud tricks a business into paying money to a criminal instead of a genuine supplier. It often arrives as a convincing email, sometimes from a compromised real account, asking to update the bank details on file, or attaching a fake invoice. The change looks routine, which is exactly why it works. Always verify a change of bank details through a channel other than the email that requested it.
Clone phishing takes a genuine email you have already received, copies it almost exactly, and resends it with the links or attachments replaced by malicious ones. Because the message matches something real, often with a plausible excuse such as resending a corrected file, it is unusually convincing. The tell is that a message you thought was already dealt with suddenly reappears.
Quishing hides a malicious link inside a QR code, often in an email or on a printed notice, so it bypasses link-scanning tools and lands on a personal phone that may be less protected. The code leads to a fake login page or a malware download. Treat an unexpected QR code with the same caution as an unexpected link.
Smishing is phishing delivered by text message, and vishing is phishing delivered by a phone call. Both use the same playbook as email phishing, impersonating a trusted organisation and creating urgency, but they move to channels people trust more and question less. A common pattern combines them with email, such as a text claiming to be your bank followed by a call to confirm the details you just gave up.
Spoofing is faking the "from" address on an email so it appears to come from someone it does not. Plain email was never built to prove who sent it, so on its own the sender name and address can be forged. The modern checks below (SPF, DKIM and DMARC) exist to catch this, which is why a domain without them is easier to impersonate.
Display name spoofing sets the friendly sender name to someone you trust, such as "Sarah, Finance", while the actual email address behind it belongs to the attacker. Many mail apps, especially on phones, show only the display name, so the fake looks genuine at a glance. Tapping or hovering to reveal the real address is the quickest way to catch it.
A lookalike domain is one deliberately registered to resemble a real one, so an email or link from it looks legitimate at a glance. Tactics include swapping letters (rn for m), using a different ending (.co instead of .com), inserting words (acme-payments.com), or using lookalike characters from other alphabets. That last trick is a homoglyph, where a Latin letter is replaced by a nearly identical one from another script.
A cousin domain is a close relative of a real domain that is plausible rather than a near-copy, such as acme-billing.com or acmesupport.net alongside the genuine acme.com. It does not rely on hard-to-spot character tricks. It relies on looking reasonable enough that nobody questions it. These are cheap to register and are a staple of invoice fraud.
SPF is a public list, published in a domain's DNS records, of which mail servers are allowed to send email for that domain. When a message arrives, the receiving server can check whether it came from an approved server. A pass is a good sign. A fail suggests the sender may be forged.
DKIM adds a cryptographic signature to each email that proves the message genuinely came from the domain it claims, and was not altered in transit. The receiving server checks the signature against a public key in the domain's DNS. A valid DKIM signature is strong evidence the email is authentic.
DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails both: allow it, quarantine it, or reject it. A domain with a strict DMARC policy is much harder to impersonate. A domain with no DMARC, or a policy of "none", offers no enforcement, so anyone can send email that appears to come from it.
A malicious link points to a fake login page, a malware download, or a site that quietly attacks your browser. The visible text can say anything, so a link that reads "view invoice" may lead somewhere entirely different. Hovering to preview the real destination, or letting a service check it first, is the safe habit before clicking.
A malicious attachment is a file that carries harmful code, disguised as an invoice, a receipt, a CV, or a shipping notice. Opening it, or enabling its content, can install malware or hand over control of your device. Unexpected attachments deserve suspicion even when the sender looks familiar, because a real account can be compromised.
A macro is a small set of automated commands built into a document such as a spreadsheet or word processor file. Macros have legitimate uses, but attackers hide harmful instructions inside them, then design the email to talk you into clicking "enable content". A document that demands you enable macros before you can read it is a classic warning sign.
Credential harvesting is the theft of usernames and passwords, usually through a fake login page that mimics a service you use. You follow a link, see a familiar sign-in screen, and type your details straight to the attacker. Stolen credentials are then used directly, sold on, or used to launch further attacks from inside a real account.
The payload is the part of an attack that actually causes harm once a victim takes the bait: the malware that installs, the page that steals a password, or the script that runs. Everything else, the convincing email and the disguised link, exists only to deliver it. Blocking delivery is why filtering links and attachments matters so much.
A drive-by download installs malware simply because you visited a web page, with no need to click anything or agree to a download. It works by exploiting a flaw in an outdated browser or plugin. Keeping software updated closes most of these gaps, which is one reason update prompts are worth acting on quickly.
Reply-to abuse sets the hidden reply-to address to the attacker while the visible sender still looks genuine. The message may even pass basic checks, but the moment you reply, your response goes to the criminal rather than the real contact. It is common in invoice fraud, where a natural exchange of replies is used to steer a payment.
Malware is a general term for any software written to damage, disrupt, or take control of a device, including viruses, spyware, and trojans. Email is one of the most common ways it spreads, hidden in attachments or behind links. Once installed, it can steal data, watch what you type, or open a door for further attacks.
Ransomware is malware that encrypts your files, or entire systems, then demands a payment to unlock them. It often enters through a phishing email or a malicious attachment, then spreads across a network. Reliable, tested backups are the single most effective defence, because they let you recover without paying a criminal.
Account takeover is when a criminal gains control of a legitimate email account, usually through a stolen or guessed password. From inside a real, trusted mailbox they can read past conversations and send convincing fraud to that person's genuine contacts. That is why these emails are so effective: they come from a real address, with real context.
Pretexting is the invented backstory that makes a scam feel legitimate, such as a supplier explaining that their bank has changed, or IT support needing to verify your login for an upgrade. The story lowers your guard and gives the harmful request a reasonable-sounding excuse. A request that arrives wrapped in an unusually detailed justification is worth a second look.
An insider threat is a risk that comes from within: a current or former employee, contractor, or partner who misuses their access, whether deliberately or by accident. In an email context, this includes someone forwarding sensitive information out, or falling for a scam that hands their access to an outsider. Limiting access to what each role actually needs reduces the damage either way.
A supply chain attack reaches a target indirectly, through a trusted supplier, partner, or piece of software rather than head on. In email, this often means a genuine supplier's account is compromised and then used to attack their customers, who have every reason to trust the sender. It is powerful precisely because the trust between the two businesses is real.
Threat intelligence is collected, shared knowledge about active threats: the domains, senders, and patterns behind current attacks. Pooled across many organisations, it lets everyone recognise a scam that others have already reported, often before it reaches them. This shared, network effect is the whole idea behind Sender Registry.
An indicator of compromise, or IOC, is a specific, concrete clue that an attack has occurred or is in progress, such as a malicious domain, a sender address, a file, or a suspicious link. IOCs are what make intelligence actionable: once one is known, it can be searched for, watched, and blocked elsewhere. Much of what Sender Registry records is, in effect, a growing catalogue of IOCs.
Sandboxing runs a suspicious file or link inside an isolated, disposable environment to see what it does, safely away from real systems. If it tries to install malware or steal data, that behaviour is caught without any real harm. It is a way to judge something by its actions rather than its appearance.
To quarantine a message is to hold it aside rather than deliver it straight to the inbox, so it can be reviewed before anyone acts on it. This gives a safety margin for anything that looks risky but is not certainly malicious. A quarantined message can then be released if genuine, or discarded if confirmed as a threat.
Multi-factor authentication, or MFA, requires a second proof of identity in addition to your password, such as a code from an app or a tap on your phone. Because a stolen password alone is then not enough to get in, MFA is one of the most effective defences against account takeover. Turning it on for email is one of the highest-value security steps a small business can take.
Zero trust is a security approach that assumes no user, device, or request should be trusted automatically, even inside your own network. Instead of trusting anything by default, each access is verified on its own merits. In everyday terms it echoes the core email habit: verify an unexpected request through a separate channel before acting, rather than trusting it because it looks familiar.
Wondering about a specific domain, sender or link? Check what the network knows.
You can change this at any time.
Every object in the registry (a sender, a domain, a campaign) moves through five stages as independent evidence builds:
This is deliberately separate from Risk and Confidence. How much of the network agrees is a different question from how dangerous something looks, or how certain we are.
Every campaign gets scored across 8 axes: infrastructure, domain patterns, message templates, link behaviour, attachment patterns, target industries, target roles, and campaign velocity. All plotted as a fingerprint.
Sender Registry compares every campaign's fingerprint against every other campaign's using cosine similarity: the same technique used to compare documents by meaning, not just matching words. A high match (we only ever suggest one above 55% similarity) means two campaigns that look unrelated on the surface may share real infrastructure, even under completely different domain names.
Senders, domains, URLs, attachments, campaigns, brands and suppliers all become nodes in a shared relationship graph, built from real evidence: a sender using a domain, a domain appearing in the same report as another domain, a report belonging to a campaign.
On a phone, we deliberately don't force a giant graph onto a small screen. Instead you get a focused view: the object you're looking at, and everything directly connected to it, with a tap to move to any of those connections in turn.
Add Sender Registry to your home screen and turn on notifications from your account - both free, both take under a minute. From then on, anything urgent (a payment-diversion campaign, an executive impersonation attempt) reaches you as a real notification on your lock screen, the same way any other app alerts you.
Every notification is sent end-to-end encrypted directly to your device - nothing is readable in transit by anyone other than your phone.
Open Verify Before You Act, point your camera at a QR code, and capture it. The image is decoded and the destination it leads to is checked exactly the same way we already check a QR code found inside a forwarded email - the same detection, just with your camera as the front door.
You'll see whether the destination is safe, blocked, or worth a second look, with a plain explanation either way.
On Android, once the app is added to your home screen, "Sender Registry" simply appears as an option in your phone's normal Share menu - the same one you'd use to send a photo to a friend. Share a suspicious text or link straight in, review it, and submit.
On iPhone, Apple's own software doesn't allow a website to appear in the Share menu automatically. A short, one-time setup (a free "Shortcut") gets you the same result - after that one step, it behaves identically on both phones.
Social engineering Manipulating people, rather than machines, into a mistake.
Social engineering is the art of manipulating people into giving up information or taking an unsafe action, rather than breaking through technology. It leans on trust, authority, urgency, fear, and helpfulness. Almost every email scam is social engineering at its core, which is why awareness matters as much as any filter.