Indicators of phishing and impersonation we flag
Beyond raw routing, a message's metadata carries tell-tale signs of a phishing or impersonation attempt. The report calls these out so you understand not just where a message came from but what it was trying to do.
Signals we look for include:
- Authentication failures (SPF/DKIM/DMARC) on a message claiming to be from a well-known brand or a person you know.
- A visible sender that mimics a trusted contact while the underlying address or Return-Path belongs elsewhere.
- Look-alike or recently-registered sender domains.
- Reply-To redirection steering your response to a different mailbox.
- Headers consistent with mass-sending infrastructure rather than a personal exchange.
Together these build a picture of intent. Establishing that a message is a deliberate impersonation — rather than a genuine but unwelcome email — often matters as much as identifying the sender when you take the matter to a provider or the authorities.

0 comments
Sign in with your TDesk account to comment.