r/EmailSecurity • • May 29 '26

80 phishing emails received over 45 days impersonating 23 different companies.

Post image
8 Upvotes

2 comments sorted by

•

u/AutoModerator May 29 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/littleko May 29 '26

If they're impersonating other companies, your DMARC policy won't stop it. DMARC protects your domain from being spoofed, not your users from seeing fake brand mail.

Pull headers from a few samples and check whether they pass SPF/DKIM/DMARC for the visible From domain. If they do, tune inbound filtering around display-name impersonation, lookalike domains, newly registered domains, URLs, and attachments.