Browse the Learning Center
Email threats
Phishing, BEC, spoofing, and the wider security landscape.
91 guides
All Email threats guides
What is phone number spoofing and how do you stop it?Phone number spoofing fakes the caller ID so a call looks like it came from someone else. See how it works, how STIR/SHAKEN fights it, and how to stop it.
Phishing-resistant MFA: does it stop device code phishing?Phishing-resistant MFA (FIDO2/WebAuthn, PKI) blocks proxy phishing by binding to a site's origin — but it does not stop device code phishing. Here's why.
What is quishing (QR code phishing) and how do you stop it?Quishing hides a malicious link inside a QR code to slip past email filters and land the attack on your phone. Here is how quishing works and how to stop it.
Business email compromise vs phishingBusiness email compromise vs phishing: classify a suspicious request by its identity and payment or access objective before acting, using the message.
How to enable phishing and malware protection in Google WorkspaceEnable phishing and malware protection in Google Workspace by configuring Gmail Safety controls, actions, organizational units, and message checks.
Spam vs phishingSpam vs phishing: spam is unsolicited bulk email, while phishing uses deception to obtain data or prompt harmful action. Learn the overlap and response.
What is a browser-in-the-browser attack?A browser-in-the-browser (BitB) attack fakes a login popup with a forged address bar to steal credentials. Here's how it works and how to spot and stop it.
Pharming vs phishingPharming redirects people to a fraudulent site through technical means. Phishing lures them there with a deceptive message. Learn the difference.
Abnormal email securityWhat Abnormal email security is, how its API-connected approach differs from a gateway and DMARC, and what to verify in an evaluation.
Avanan email securityAvanan email security is Check Point's API-based inline protection for supported SaaS email. Learn what it examines and what it does not prove.
Barracuda email securityWhat Barracuda Email Protection covers, how it relates to DMARC, and what to verify when evaluating it for Microsoft 365 or Google Workspace.
Sublime email securityUnderstand Sublime email security's documented scope, what it does not prove in a tenant, and how to evaluate it alongside sender-domain authentication.
Zix email security: what the name means todayLearn what Zix email security refers to today, how its OpenText encryption service works, and why it does not replace DMARC.
What Is an Anti-Phishing Program? Components and Operating ModelBuild an anti-phishing program with clear owners, layered controls, safe reporting, incident handoffs, useful metrics, and a review cadence.
Anti-Phishing Software for Business: How to Compare Email Protection ToolsCompare Microsoft, Google, Proofpoint, Cloudflare, and Abnormal anti-phishing software by deployment, coverage, operations, and buying fit.
What is ping spoofing and does it matter?Ping spoofing means faking your network latency — a PvP game cheat, and separately an ICMP source-address trick. Here is what each one is and when it matters.
Why does Outlook show an unverified sender warning?Outlook marks a sender unverified when it cannot confirm the displayed identity. Diagnose SPF, DKIM, DMARC alignment, and the actual sending path.
Why does Gmail say "Be careful with this message"?Gmail's "Be careful with this message" warning often points to failed authentication. Read the banner, inspect headers, and fix SPF, DKIM, or DMARC.
What is a quid pro quo attack?A quid pro quo attack trades a fake favour — IT help, a gift, a job — for your credentials or access. Here is how it works and how to stop it.
What is piggybacking in cybersecurity?Piggybacking in cybersecurity is when an authorized person knowingly lets an unauthorized one into a restricted area — how it differs from tailgating.
Is Have I Been Pwned safe to use?Have I Been Pwned is safe to use: it never logs your searches, and the password checker uses k-anonymity so your password never leaves your device.
What is a honeytrap scam and how do you spot one?A honeytrap scam uses a fake romantic or friendly connection to manipulate a target into sending money or leaking data. Learn how to spot one.
Why am I getting fake payment confirmation emails?Fake payment confirmation emails are phishing that fakes a receipt to make you call a fraud number or cancel a charge. Learn to spot and stop them.
What is pharming and how do you prevent it?Pharming redirects you to fake websites by corrupting DNS or your hosts file to steal logins. Learn how pharming works and how to prevent it.
Why am I getting fake law enforcement emails?Fake law enforcement emails are a phishing scam: a July 2026 campaign impersonates Interpol to push ransomware at small businesses. How to spot and stop them.
Spam vs phishing: what's the difference?Spam is unsolicited bulk messaging. Phishing uses deception to steal information or trigger a harmful action. Learn the overlap and the right response.
Spoofing vs phishing: what's the difference?Spoofing fakes identity. Phishing uses deception to make someone act. Learn where they overlap and which email controls address each risk.
What is URL spoofing and how can I stop it?URL spoofing uses lookalike web addresses to steal logins and spread malware. Learn how fake URLs work, how to spot them, and how MSPs can block them.
What are rogue apps and how can I stop them?Rogue apps are malicious OAuth apps that bypass MFA via consent phishing. How MSPs detect, remove, and prevent illicit consent grants in Microsoft 365 and
How does dark web activity threaten organizations?Dark web markets sell stolen credentials that fuel ransomware and BEC. How the trade works, what monitoring can and can't do, and how MSPs should respond.
How does sandboxing help stop malware?FAQ: sandboxing basics, how it works, benefits, and where to use it in security stacks.
How fast should your team respond to incidents (MTTR)?A concise guide to Mean Time to Respond (MTTR) in cybersecurity: definition, calculation, and tactics to lower response times.
How does malspam work — and how can organizations stop it?Learn what malspam is, how it operates, and clear defensive steps IT teams can use to stop it.
Why should organizations run regular phishing simulations?Why perform routine phishing simulations, the best practices, and quick steps to strengthen employee detection and reporting.
Can Rockstar 2FA bypass Microsoft 365 MFA?Rockstar 2FA is a phishing-as-a-service kit that steals M365 session cookies to bypass MFA. How the AiTM attack works and what actually stops it.
Is November’s shopping frenzy the prime time for cyber scams?November shopping spikes cyber scams. Learn the top threats, real examples, and practical steps MSPs and SMBs can take to reduce risk.
Why does healthcare data attract ransomware attackers so often?Why healthcare records draw ransomware attacks and what IT teams can do to reduce risk and recover quickly.
How can healthcare organizations stop ransomware?Practical steps healthcare teams can take to reduce ransomware risk: backups, MFA, training, segmentation, and monitoring.
How long should organizations retain EDR data for investigations?How long to keep EDR data: vendor defaults (14-30 days), what PCI DSS and HIPAA require, and how to size retention to real attacker dwell times.
How can attackers exploit OAuth device code login?How attackers exploit Device Code flow, what risks that creates, and practical mitigations for security teams.
How do you choose the right endpoint security solution?How to choose endpoint security: what EDR must include, how to read MITRE and AV-Comparatives tests, vendor questions for MSPs, and rollout steps.
How could the Israel–Iran cyber war affect U.S. companies?How the Israel–Iran cyber conflict, hacktivism, and AI disinformation create risks for U.S. companies — and what security teams should do now.
How can you simulate fileless credential dumping?Practical Q&A on simulating in-memory credential theft to validate endpoint protections and incident response.
Can attackers use trusted installers to blind EDR?How attackers hide payloads inside legitimate installers to bypass endpoint detection and create blind spots; detection and mitigation steps for IT teams.
How did ShinyHunters use vishing and OAuth abuse to breach the cloud?How social engineering and OAuth token misuse let attackers access cloud CRM data — and what security teams should do now.
How can organizations stop the top identity-related threats?Explore the leading identity threats—BEC, credential stuffing, ATO, auth bypass—and how MSPs can prevent them with MFA, least privilege, MDR, and DMARC.
How is security innovation reshaping managed security services?Explore platform updates: ITDR for Google Workspace beta, phishing simulations at scale, one-click agent uninstall, AI improvements, and recent awards.
How are identity threats evolving against Google Workspace in 2025?Identity attacks on Google Workspace surged in 2025. Learn key trends, defenses, quick takeaways, and FAQs for IT teams.
DoS vs DDoS Attacks: What's the Difference?DoS vs DDoS: a DoS attack floods a target from one source, a DDoS from thousands of botnet devices. Compare scale, tracing, blocking, and defenses.
What are the easiest ways to protect your business data?Learn ten easy data protection solutions, from firewalls to user behavior analysis, to keep your business safe from breaches.
What Are the Best Email Security Practices for Businesses?Discover essential email security best practices for businesses, including DMARC, DKIM, SPF, MFA, and employee training.
What Are the Five Stages of Penetration Testing?Learn the five stages of penetration testing, from planning to retesting, and why each step is crucial for protecting your business against cyber threats.
How Can You Move from Reactive to Proactive Email Security Posture?Learn how to transition from reactive to proactive email security with expert Q&A from our webinar. Get actionable steps for DMARC, DKIM, SPF, and BIMI.
How Secure Is Your Email Communication Today?Discover how email works, the main security threats, and actionable steps like DMARC, encryption, VPN, and MFA to protect your messages.
Why a single solution can’t stop ransomware?Discover why ransomware evolves, the limits of single defenses, and practical steps to protect your organization with layered security.
What are the 14 most common social engineering attacks?Discover the 14 types of social engineering attacks, their tactics, and effective defenses to keep your business safe.
What Are the Top Email Security Tips for Small Businesses?Small businesses rely heavily on email, making them prime targets for cybercriminals.
What is a computer worm and how does it spread?A computer worm is a self‑replicating piece of malicious software that spreads without needing to attach to a host file.
Why are 97% of Indonesian domains vulnerable to cyberattacks?Recent analysis of Indonesia’s country‑code top‑level domains (ccTLDs) shows a staggering security gap.
What is Whaling Phishing and How Can You Prevent It?Whaling phishing is a targeted email fraud that pretends to be a senior executive or high‑level official in order to trick recipients into revealing…
What is an impersonation attack and how can you stop it?Impersonation attacks are a form of social engineering where a malicious actor pretends to be a trusted person—often a senior executive or a known…
How Can You Safely Handle Malicious Email Attachments?Look for unexpected file types, executable extensions (.exe, .bat), or mismatched file names.
How can secure email gateways protect my organization?Secure Email Gateways (SEGs) act as a protective shield that scans every incoming email before it lands in your users’ inboxes, blocking spam, phishing…
What Were the Major Email Security Highlights in September 2021?September 2021 saw a flurry of email‑related security news, ranging from regulatory actions to new protection tools. What regulatory action did the U.S.
What Were the Key Email Security Highlights in October 2021?Cybersecurity Awareness Month, launched by the U.S. Department of Homeland Security, runs every October to promote best practices in digital safety.
Why are targeted email attacks so hard to stop?Targeted email attacks—often called spear‑phishing—are engineered to look like legitimate communication, making them notoriously hard to detect and stop.
How Does Business Email Compromise (BEC) Threaten Your Business?Business email compromise (BEC) is a social‑engineering attack where cybercriminals target corporate email accounts to trick employees into sending money…
What Exactly Is Spoofing and How Can You Stop It?Spoofing is a broad term for attacks where cybercriminals pretend to be a trusted source—whether an email sender, website, or even a phone number—to trick…
How can you stop spoofing attacks?Imagine you get an urgent email that looks like it’s from your insurance provider, asking for personal details.
How Does IP Spoofing Work and How Can You Stop It?IP spoofing remains a stealthy technique that lets attackers disguise their true location.
How can I take down lookalike domains targeting my business?You’ve built a trusted brand, invested years in customer relationships, and worked hard to establish credibility.
What were the biggest email security headlines in April 2022?Welcome back to our weekly security roundup. This week’s focus is on three major email‑related incidents that could impact your organization’s defenses.
How can you spot fake emails and protect yourself from scams?Phishing attacks are getting more sophisticated, but you can protect yourself by learning to spot the red flags in fake emails.
How dormakaba keeps email security strong at scaleMergers and acquisitions (M&A) can boost growth, expand market share, and streamline supply chains.
Why must NZ government domains adopt new email standards?New Zealand’s Digital Government has released the Secure Government Email (SGE) Framework, a modern set of technical controls that replace the legacy…
Spear phishing vs phishing: key differences in 2025Spear phishing vs phishing: how targeting, research, and payloads differ, why each one gets through, and the layered defenses that stop both.
What is a whaling attack and how can you stop it?Whaling attacks are highly targeted phishing attempts aimed at the most senior leaders within an organization—CEOs, CFOs, board members, and other…
Business Email Compromise (BEC) attacks: 2025 guideYou receive an urgent email from your CEO requesting a wire transfer. It looks legit—right email address, familiar language, and insider details.
What Is Angler Phishing and How Can You Stop It?Angler phishing uses fake social-media support accounts to bait frustrated customers. Learn how the attack works, the warning signs, and how to shut it down.
What is email impersonation and how can you prevent it in 2025?Email impersonation isn’t just an IT problem. It’s a silent storm, quietly eroding your brand’s reputation, customer trust, and financial stability.
What are the 3 types of email impersonation attacks?The cost of Business Email Compromise (BEC) totaled more than $50 billion over a nine-year period ending July 2019, according to the FBI.
How can you protect your brand from impersonation with anti‑spoofing?Anti‑spoofing technology and features might not be the flashiest part of your email stack, but they can make or break your email program—and your brand’s…
What is email spoofing and how can you prevent it?Email spoofing is a deceptive practice cybercriminals use to disguise their identity by altering the sender information in emails.
How can AI and zero trust improve email security?Email security isn’t what it used to be. Today’s cybercriminals wield AI to craft phishing emails that can fool even senior executives.
What is TLS? Transport Layer Security ExplainedLearn how TLS protects your data with encryption, authentication, and integrity checks.
What is a Firewall? Network Security Basics ExplainedDiscover what firewalls are, how they work, and why they’re crucial for network security.
What is an email Alias? Uses, Setup and SecurityDiscover what an email alias is and how it organizes your inbox.
What is Spear Phishing? Targeted Attacks ExplainedSpear phishing is a targeted email attack that impersonates someone you trust. Learn how it works, why it succeeds, and how to defend against it.
What is Malware? Types, Examples and PreventionExplore malware, harmful software spread via phishing, and how SPF, DKIM, DMARC protect you.
What is Spoofing? Email Spoofing Attacks ExplainedLearn about spoofing, fake email attacks, and how to protect with email authentication.
What is Phishing? Attack Types and Prevention GuideWhat phishing is, how the attack works step by step, the main types, and how SPF, DKIM, and DMARC plus user training stop it.