Glossary
Attacks
Display-name spoofing
Putting a trusted name in the human-readable part of the From header while the actual address belongs to the attacker. No email-authentication protocol addresses this, because the address really does belong to the sender.
Defined in M3AAWG best practice.
Where this appears
The lessons that use this term, and what each is for.
Email Authentication FundamentalsWhy spoofing works at allExplain precisely which part of SMTP fails to authenticate the sender, and what a receiver can check without help.Email Authentication FundamentalsWhat p=reject does not stopName the impersonation techniques that survive full DMARC enforcement, and say what does address them.Email Security PractitionerResidual risk after rejectState precisely what remains possible against a domain at full enforcement.Domain Abuse & ImpersonationDeception that needs no registrationRecognise the impersonation techniques that require no lookalike domain at all.Domain Abuse & ImpersonationWhat monitoring cannot seeName the impersonation techniques no domain monitoring will ever surface.Domain Trust ArchitectureWhat each one leaves openState, for every control, the attack it does not address.