An attacker may manipulate the visible display name, use an unauthorized address in the From field, send through a lookalike domain, or create a reply path that leads somewhere unexpected.
Different forms require different defenses. SPF, DKIM, and DMARC can help receiving systems detect unauthorized use of a protected domain, but they do not stop display-name impersonation or a newly registered lookalike domain. Visual inspection alone is also unreliable on small screens or where mail clients hide address details.
Key points
Direct domain spoofingThe message claims to use a domain the attacker does not control.
Lookalike domainThe attacker registers a similar but distinct name, so authentication may succeed for the attacker’s own domain.
Display-name spoofingThe friendly name imitates a person or brand while the underlying address differs.
Important limitationSpoofing does not require account compromise, and account compromise does not require spoofing; a genuine mailbox can send a fraudulent request.