Glossary
Attacks
Spoofing
Sending a message that claims an identity the sender is not entitled to. In email this is trivial at the protocol level, because SMTP accepts whatever addresses it is given.
Defined in RFC 7960 §2.
Where this appears
The lessons that use this term, and what each is for.
Email Authentication FundamentalsWhy spoofing works at allExplain precisely which part of SMTP fails to authenticate the sender, and what a receiver can check without help.Advanced Email TrustWhat authentication does not buySeparate the delivery problems authentication fixes from the ones it cannot touch.Advanced Email TrustComplaints and list hygieneName the two numbers receivers actually act on, and what moves each.Email Security PractitionerA spoofing campaignWork an active spoofing campaign in the order that ends it fastest.Email Security PractitionerExplaining it to people who do not run DNSDescribe the exposure and the fix without analogies that will be quoted back at you wrongly.Email Security PractitionerResidual risk after rejectState precisely what remains possible against a domain at full enforcement.Email Security PractitionerQuestions this is the wrong answer toRecognise the problems people will bring to you that authentication cannot address.Domain Abuse & ImpersonationThe MX that changes everythingExplain why an MX record on a lookalike is the single strongest escalation signal.Domain Abuse & ImpersonationWhat monitoring cannot seeName the impersonation techniques no domain monitoring will ever surface.Domain Trust ArchitectureThe four surfacesPlace any control on one of four surfaces, and say which surface a given attack targets.Domain Trust ArchitectureWhat each one leaves openState, for every control, the attack it does not address.Domain Trust ArchitectureMaking the caseArgue for the work without scare tactics, and act usefully when the answer is no.Domain Security PractitionerThe conversationPresent the findings so the free work starts this week and the rest is scheduled.