Malware

Phishing

Phishing is a message or page that impersonates someone you trust to get a password, a payment, or a click. The lure may be mail, SMS, a chat message, or a fake login page.

How it is measured

Check the sender and the destination separately. Read the full headers for SPF, DKIM, and DMARC results, compare the visible link text with the real href, and look up the link domain's age and registrar. A login page on a host that is not the vendor's domain is the clearest sign.

On the web side, phishing kits show up as a lookalike page with copied images and a form that posts to a script. Report URLs to the brand and to browser safe-browsing lists, and note how long the page stayed up.

Worked example

An accounts clerk gets 'Your Microsoft 365 password expires in 24 hours' from a hacked school address. The button goes to a form hosted on a free website builder, with the Microsoft logo hotlinked. The form posts the password to /submit.php and then redirects to the real login page.

The mail passed SPF because it truly came from the hacked school's server. That is why the clerk's glance at the sender name was not enough; the URL was the only reliable tell.

How it differs

Spear phishing is aimed at a named person with details the attacker researched. Phishing in general is sent wide with a generic lure and relies on volume. Both end in a stolen credential or a payment; the targeted one gets a better-written message and far fewer recipients.

Common errors

Trusting the display name. Believing a padlock means the site is legitimate. Checking links by hovering on a phone, where you cannot. Reporting the message and then clicking it anyway. Training staff but never turning on multi-factor authentication or checking for reused passwords.

In practice

Turn on phishing-resistant sign-in such as passkeys or hardware keys for admin accounts, publish SPF, DKIM, and DMARC for your domain so nobody can spoof it, and give staff one place to forward suspicious mail. If someone does enter a password, change it immediately and review recent sign-ins.

See also

Spear phishing, Clone phishing

Sources

Count this on a real site.

Watch my website