Glossary
Attacks
Cousin domain
A domain registered by an attacker that resembles the target closely enough to deceive a reader, and which the attacker authenticates correctly. DMARC on the real domain has no bearing on it.
Defined in RFC 7960 §2.
Where this appears
The lessons that use this term, and what each is for.
Email Authentication FundamentalsWhat p=reject does not stopName the impersonation techniques that survive full DMARC enforcement, and say what does address them.Email Security PractitionerResidual risk after rejectState precisely what remains possible against a domain at full enforcement.Domain Security FundamentalsCombosquatting, and why it is harderExplain why brand-plus-word domains defeat the defences that work against typos.Domain Abuse & ImpersonationThe attacker’s arithmeticState what a lookalike campaign costs to run, and what it has to return to be worth running.Domain Abuse & ImpersonationDeception that needs no registrationRecognise the impersonation techniques that require no lookalike domain at all.Domain Abuse & ImpersonationThe MX that changes everythingExplain why an MX record on a lookalike is the single strongest escalation signal.Domain Abuse & ImpersonationFour outcomesPlace any suspicious domain into one of four categories from the evidence available.Domain Abuse & ImpersonationRanking a queueOrder a day’s findings so the one that matters is worked first.Domain Trust ArchitectureWhat each one leaves openState, for every control, the attack it does not address.Domain Security PractitionerThe impersonation exposureQuantify what is being registered against the brand using only public data.