Module 1 of 4
Phishing and BEC: How Spoofing Gets Used
Courses 1 and 2 covered the mechanics – SPF, DKIM, DMARC, MTA-STS, DNSSEC. This module covers why any of it matters in terms that show up on a balance sheet, not just a DNS record.
Phishing: broad and opportunistic
Classic phishing casts a wide net – an email impersonating a known brand (a bank, a shipping carrier, a SaaS login page) tries to get a recipient to click a link and enter credentials or payment details on a fake page. Volume matters more than precision; even a low success rate across a huge send is profitable for the attacker.
BEC: narrow, targeted, and far more costly per incident
Business Email Compromise is a fundamentally different shape of attack. There's often no malware and no link at all – just a well-crafted message that looks like it's from a real executive, vendor, or attorney, asking for a wire transfer, a change to payroll banking details, or a batch of gift cards "before the end of the day." The FBI's own IC3 reporting has consistently ranked BEC among the costliest categories of reported cybercrime, specifically because a single successful incident can move real money directly, with no ransomware or data-theft step in between.
Two ways a BEC message gets its identity
- Direct header spoofing – if the target domain has no enforced DMARC, an attacker can put the real executive's exact email address in the header
From:and have it delivered as if genuinely sent from that domain. - Lookalike domain registration – if DMARC is enforced, direct spoofing gets blocked, so the attacker takes the next step: register a domain that looks confusingly similar to the real one, and send from that instead. DMARC protects your domain from being impersonated directly – it does nothing about a different domain someone legitimately registered that merely looks like yours.
That second pattern is common enough, and distinct enough from anything DMARC covers, that it gets its own module next.
Try it yourself: Phishing Link Checker