Spoofing
Forging a sender's identity: email, domain, phone number or website. It is the technical layer that makes impersonation believable.
Full definition
Spoofing is the technical forgery of a digital identity so that a message or connection appears to come from a trusted source. Attackers can forge an email sender, a whole domain, a phone number or a website.
In email, the attacker forges headers or registers domains that look visually similar to the legitimate one, with swapped or added characters. The SPF, DKIM and DMARC protocols exist to authenticate message origin, but many companies have them misconfigured or without an enforcement policy, which leaves the door open.
Spoofing is rarely the whole attack: it is the layer that makes phishing, BEC or vishing believable. Defense therefore combines correct configuration of those protocols with the habit of checking the real domain before replying or clicking.
Related terms
Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Business email compromise (BEC)
Fraud where the attacker poses as an executive or vendor from a legitimate or spoofed mailbox to divert payments or data. It usually carries no malware.
Vishing
Social engineering over a phone call. The attacker poses as tech support, a bank or a vendor to obtain access or payments in real time.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.