Browse the Learning Center
Email threats
Phishing, BEC, spoofing, and the wider security landscape.
103 guides
All Email threats guides
Apple phishing email: how to verify and report itApple never asks for your password or a verification code by email. Check the claim in Settings or at appleid.apple.com, then report the message to Apple.
Bank of America phishing email: verify it safelyBank of America will not ask for your PIN or password by email. Verify any transaction in the app or by calling the number on your card, then report it.
Docusign phishing email: verify an envelope safelyNever use the link in a suspect Docusign email. Open Docusign independently if you have an account, verify the envelope there, then report the message.
Geek Squad phishing email: check a renewal or invoiceFake Geek Squad renewal invoices are the classic version of this scam. Check subscriptions in your Best Buy account, never call the number in the email.
Gmail report phishing steps and what happens nextFollow Gmail's current report phishing steps, learn what Google receives, preserve useful evidence, and know when your security team must be involved.
How do I avoid phishing emails and what habits keep me safer?Verify every urgent request through a channel the message did not supply, keep MFA on every account, and report suspicious mail rather than deleting it.
How to block phishing emails: filters, rules, and limitsSender blocks, mailbox rules, and spam reports stop known senders. None stop a spoofed domain, which needs DMARC enforcement at the organization level.
How do I report a phishing email in Outlook?Use Report, then Report phishing in new Outlook and on the web, or the Report Message add-in in classic Outlook. Tell IT if you clicked or entered data.
How do I spot a phishing email before I click?Check what the message asks for, whether the sender domain really matches, where its links point, and whether you expected it. Verify outside the message.
IRS phishing email: how to verify and report itThe IRS does not open contact by email about a refund or a debt. Verify any tax claim through official government channels, then report the message.
Microsoft phishing email: how to check it safelyMicrosoft will not ask for your password or MFA code by email. Check sign-in activity at account.microsoft.com, then use Report phishing inside Outlook.
Netflix phishing email: verify billing and account alertsNetflix will not ask for card details by email. Check billing and account status by signing in at netflix.com directly, then report and delete the message.
Phishing email examples: ten patterns to inspectReview ten realistic phishing email examples, compare their warning signs, and learn how to verify suspicious requests without using the message.
What is a phishing email? Meaning and safe responseA phishing email impersonates someone you trust to make you act: click, pay, or hand over credentials. Verify the request outside the message first.
Yahoo phishing email: how to check it safelyYahoo will not ask for your password or account key by email. Check recent activity in Yahoo Account Security, then report the message and delete it.
Google Forms spam: stop it and spot itGoogle Forms spam comes two ways: junk submissions to your own form, and deceptive forms sent to you. How to stop both, and how to judge a forms.gle link.
Caution: this email originated from outside of the organization"Caution: This email originated from outside of the organization" means the message is external, not that it is phishing. Here is what to check.
Email sender spoof: how to spot and stop itEmail sender spoofing forges the visible From field. Learn which trusted header results expose it, why SPF alone is insufficient, and how DMARC helps.
Pixm phishing protectionPixm phishing protection is browser-layer protection that Pixm says uses AI computer vision to stop credential phishing from email, SMS, LinkedIn, and.
What is an anti-phishing program?Anti phishing program: an operating model for ownership, controls, reporting, response, and measurement that reduces organizational phishing risk.
Anti-phishing software: how to compare business toolsAnti phishing software comparison for businesses: evaluate native controls, dedicated email security, DMARC, and sender-domain protection options.
Business email compromise is financially motivatedBusiness email compromise attacks are financially motivated scams that seek unauthorized fund transfers, not typically disruption-motivated attacks or.
Is business email compromise the most expensive cyberattack?Business email compromise ranks second by total losses in the FBI's 2025 figures, behind investment fraud, but leads every category on loss per complaint.
Can email addresses be spoofed?Can email addresses be spoofed? Yes. Learn how displayed From addresses can be forged, how DMARC helps, and how to check a suspicious email.
Email security testing tools: run, interpret, repair, retestEmail security testing tools help safely test gateway handling of safe threats, interpret blocking or disarming results, repair gaps, and retest.
Email spoofing in cyber securityEmail spoofing in cyber security is the use of a forged email identity to make a message appear to come from a trusted sender and domain.
ESET anti-phishing protection is non-functionalESET anti-phishing protection is non-functional when its product-specific status needs diagnosis. Identify the product, symptom, and official support path.
Gmail phishing protectionGmail phishing protection combines Gmail warnings with careful verification and reporting. Learn what to check before you click or respond today.
How to block spoofed emailsHow to block spoofed emails: use separate inbound email-security controls and domain-authorization controls instead of relying on one blocked message.
Norton phishing protection: what Scam Protection confirmsNorton phishing protection includes advertised Scam Protection on selected plans, but Norton does not document phishing-email coverage or guarantees.
O365 phishing protectionO365 phishing protection requires current Microsoft documentation for the tenant's licensed controls, policies, reporting options, and validation evidence.
Phishing protection for Office 365Phishing protection Office 365 requires tenant-specific controls, user reporting, and evidence from real messages. Learn what to verify for your tenant.
The goals of email spoofing include luring the user intoThe goals of email spoofing include luring users into sharing credentials, financial details, or visiting malicious sites through a trusted-looking.
ThreatDown browser phishing protectionThreatDown browser phishing protection is listed in its pre-delivery layer. See how it differs from email security and DNS filtering for domain owners.
What is URL spoofing and how can I stop it?URL spoofing uses deceptive web addresses to send people to attacker-controlled sites. Learn how to inspect links and reduce phishing risk safely.
What is quishing (QR code phishing) and how do you stop it?Quishing is QR code phishing that hides a malicious link in a scannable image. Learn how to identify it and reduce the risk of credential theft.
AI powered email security: what the label actually coversAI powered email security covers content and behavior models, not domain authentication. See what vendors document, and how to test any AI claim.
Cisco advanced phishing protectionUnderstand Cisco Advanced Phishing Protection, its gateway sensor flow, current support limits, and the tenant evidence needed to verify coverage.
Email security for small business: what actually matters firstThe working order for small business email security: MFA first, then the controls Microsoft 365 and Google Workspace already include, then DMARC.
How can you protect your brand from impersonation with anti-spoofing?Protect your brand from impersonation with anti-spoofing by aligning SPF and DKIM, enforcing DMARC carefully, and recording response evidence.
How does IP spoofing work and how can you stop it?IP spoofing works by forging a packet's source address. Learn how ingress filtering, source validation, and authentication reduce its impact.
Pharming vs phishingPharming vs phishing: phishing uses a deceptive lure, while pharming redirects users to a fraudulent site through technical means. Learn the difference.
Phishing protection browser add onSet up a phishing protection browser add on safely, review permissions, validate the control, and keep a rollback path.
What is angler phishing and how can you stop it?Angler phishing uses fake social-media support accounts to exploit public complaints. Learn how to verify support and limit email impersonation.
What is phone number spoofing and how do you stop it?Phone number spoofing falsifies caller ID. Learn how spoofed calls work, how to respond safely, and what carrier authentication can do today.
What are business email compromise (BEC) attacks and how do you stop them?Business Email Compromise (BEC) attacks impersonate trusted people or vendors to redirect money or data. Learn the warning signs and controls.
Why is phishing so effective?Phishing works by pairing trusted-looking context with pressure and a simple requested action. Learn how to interrupt the decision safely.
Best email security: 8 options comparedBest email security: 8 options checked on deployment model, threats named and published pricing, from first-party vendor pages read on 12 August 2026.
Email security software: how to choose a category fitEmail security software covers four types: secure email gateways, API-connected tools, native provider controls, and the DMARC layer. Find your fit.
Mimecast email security: what it does and what it cannot proveMimecast email security is a vendor email-security offering, but its name alone cannot prove a specific email is safe, encrypted, or legitimate.
Phishing attack protection: the controls that actually workPhishing attack protection combines phishing-resistant MFA, DMARC enforcement, user training, and reporting; no single control stops every attempt.
Phishing scam email example: how to assess one safelyPhishing scam email examples reveal sender, urgency, and link clues. Learn how to inspect a suspicious email and verify it safely for safer decisions.
What is an impersonation attack and how can you stop it?An impersonation attack poses as a trusted person or domain to obtain money, data, or access. Learn how to identify, contain, and reduce email.
Advanced Email Security from GoDaddyAdvanced Email Security from GoDaddy is a Microsoft 365 email protection service with spam, phishing, quarantine, and encryption controls for tenants.
Amazon report phishing emailReport a suspicious Amazon email to stop-spoofing@amazon.com, learn the claims these messages make, and verify any order notice inside Amazon itself.
Cloud based email securityCloud based email security adds a cloud-delivered protection layer around cloud mailboxes. Assess the controls included before selecting a service.
Email security Proofpoint: what Core Email Protection coversEmail security Proofpoint refers to Proofpoint's Core Email Protection, with API and secure email gateway options. Learn what evidence to request.
Email security protocolsEmail security protocols protect different parts of email: transport, mailbox access, and domain authentication. See how TLS, SMTP, SPF, DKIM, and DMARC.
How do you move from reactive to proactive email security?How to move from reactive to proactive email security: establish an authenticated sending baseline, validate real mail, and review change evidence.
How to keep email authentication strong through multiple acquisitionsEmail authentication stays strong through acquisitions when teams inventory domains and senders, assign ownership, validate mail, and phase DMARC.
Paypal phishing scam emailPaypal phishing scam emails should be verified outside the message. Learn how to separate an impostor email from an unfamiliar PayPal request.
Where to report a phishing email and what each route doesReport email phishing scams to the route that can act: your mailbox provider, your workplace, the impersonated brand, or a US reporting body.
Report a Social Security phishing emailReport a Social Security phishing email safely: do not reply, pay, or share information. Verify any reporting destination is an official government site.
What are the 3 types of email impersonation attacks?Email impersonation attacks commonly use an exact domain, a lookalike domain, or a free-mail account. Learn how each type works. Learn what to verify.
What are the top email security tips for small businesses?Email security tips for small businesses: use MFA, verify sensitive requests, authenticate sending domains, and test recovery paths safely today.
What exactly is spoofing and how can you stop it?Spoofing is impersonation that makes a message, call, website, or network request appear trusted. Learn how to identify and limit spoofing for your domain.
What is email spoofing and how can you prevent it?Email spoofing forges sender details to make mail look trusted. Stop spoof emails with SPF, DKIM, DMARC enforcement, header checks, and user reporting.
What is a whaling attack and how can you stop it?What is a whaling attack? It is targeted phishing aimed at senior leaders. Learn how to verify requests and reduce email impersonation risk.
What is whaling phishing and how can you prevent it?Whaling phishing is a targeted impersonation attack against executives or people who can approve payments. Learn how to verify and reduce the risk.
What is an email security gateway?An email security gateway inspects mail before it reaches recipients. It runs in front of the mailbox, alongside it via an API, or inside the platform.
Phishing-resistant MFA: does it stop device code phishing?Phishing-resistant MFA (FIDO2/WebAuthn, PKI) blocks proxy phishing by binding to a site's origin, but it does not stop device code phishing. Here's why.
Business email compromise vs phishingBusiness email compromise vs phishing: classify a suspicious request by its identity and payment or access objective before acting, using the message.
How to enable phishing and malware protection in Google WorkspaceEnable phishing and malware protection in Google Workspace by configuring Gmail Safety controls, actions, organizational units, and message checks.
Spam vs phishingSpam vs phishing: spam is unsolicited bulk email, while phishing uses deception to steal information or prompt harmful action from recipients.
What is a browser-in-the-browser attack?A browser-in-the-browser (BitB) attack fakes a login popup with a forged address bar to steal credentials. Here's how it works and how to spot and stop it.
Abnormal email securityAbnormal email security is an API-connected cloud email-security offering. Compare its buyer evidence with gateway and DMARC boundaries in practice.
Avanan email securityAvanan is Check Point's API-based email protection. What it inspects, where it sits in your mail flow, and what it doesn't do for domain authentication.
Barracuda email securityBarracuda email security: compare Barracuda Email Protection with Palisade by deployment scope, DMARC workflow, buyer fit, and DMARC evidence.
Sublime email securityUnderstand Sublime email security's documented scope, what it does not prove in a tenant, and how to evaluate it alongside sender-domain authentication.
Zix email security: what the name means todayZix email security now sits within OpenText Cybersecurity. Learn what its encryption service does and where SPF, DKIM, and DMARC differ today.
What is ping spoofing and does it matter?Ping spoofing means faking network latency, a PvP game cheat, and separately an ICMP source-address trick. What each is, and which one actually matters.
What is a quid pro quo attack?A quid pro quo attack trades a fake favour (IT help, a gift, a job) for your credentials or access. Here is how it works and how to stop it.
What is piggybacking in cybersecurity?Piggybacking in cybersecurity is when an authorized person knowingly lets an unauthorized one into a restricted area. How it differs from tailgating.
Is Have I Been Pwned safe to use?Have I Been Pwned is safe to use: it never logs your searches, and the password checker uses k-anonymity so your password never leaves your device.
What is a honeytrap scam and how do you spot one?A honeytrap scam uses a fake romantic or friendly connection to manipulate a target into sending money or leaking data. Learn how to spot one.
What is pharming and how do you prevent it?Pharming redirects you to fake websites by corrupting DNS or your hosts file to steal logins. Learn how pharming works and how to prevent it.
Why am I getting fake law enforcement emails?Fake police and Interpol emails are phishing built on fear and urgency. How to recognise one, what never to click, and how to stop them reaching staff.
Spoofing vs phishing: what's the difference?Spoofing vs phishing: spoofing fakes an identity, while phishing uses deception to prompt a harmful action. Learn how email authentication fits.
What are rogue apps and how can I stop them?Rogue apps are malicious OAuth apps that bypass MFA via consent phishing. How MSPs detect, remove, and prevent illicit consent grants in Microsoft 365 and
How does sandboxing help stop malware?FAQ: sandboxing basics, how it works, benefits, and where to use it in security stacks.
How fast should your team respond to incidents (MTTR)?A concise guide to Mean Time to Respond (MTTR) in cybersecurity: definition, calculation, and tactics to lower response times.
How does malspam work, and how can organizations stop it?What malspam is, how attackers use spam to deliver malware, and the defensive steps IT teams can take today: filtering, authentication, and training.
Can Rockstar 2FA bypass Microsoft 365 MFA?Rockstar 2FA is a phishing-as-a-service kit that steals M365 session cookies to bypass MFA. How the AiTM attack works and what actually stops it.
How long should organizations retain EDR data for investigations?How long to keep EDR data: vendor defaults (14-30 days), what PCI DSS and HIPAA require, and how to size retention to real attacker dwell times.
How can attackers exploit OAuth device code login?How attackers exploit Device Code flow, what risks that creates, and practical mitigations for security teams.
How did ShinyHunters use vishing and OAuth abuse to breach the cloud?How ShinyHunters combined vishing and OAuth token abuse to reach cloud CRM data, and the controls security teams should put in place now to stop a repeat.
How are identity threats evolving against Google Workspace in 2025?Identity threats in Google Workspace: OAuth app abuse, credential leaks, and session hijacking, with the admin controls and alerts that stop each one.
What Were the Major Email Security Highlights in September 2021?September 2021 saw a flurry of email-related security news, ranging from regulatory actions to new protection tools. What regulatory action did the U.S.
What Were the Key Email Security Highlights in October 2021?Cybersecurity Awareness Month, launched by the U.S. Department of Homeland Security, runs every October to promote best practices in digital safety.
How can AI and zero trust improve email security?Email security isn’t what it used to be. Today’s cybercriminals wield AI to craft phishing emails that can fool even senior executives.
What is spear phishing and how do you defend against it?Spear phishing is a targeted email attack that impersonates someone you trust. Learn how it works, why it succeeds, and how to defend against it.
What is spoofing and what are the types of spoofing attacks?Spoofing is impersonation that falsifies an email, IP, or caller identity. Learn how email spoofing works, how to verify it, and what to check.
What is phishing and what are the types of phishing attack?What is phishing? It is a deceptive message or site that steals data or prompts harmful actions. Learn common attack types and prevention steps.