Three distinct mechanisms

Domain spoofing claims a sender domain the sender is not authorized to use. Lookalike-domain impersonation uses a different domain resembling a trusted one. Account compromise uses access to a genuine mailbox or authorized sending system. These mechanisms need different evidence and containment actions.

A familiar display name does not authenticate a sender. A message that passes SPF or DKIM can still contain an unauthorized payment instruction. Establish the addresses and authenticated domains first, then investigate whether the business request was authorized.

Read headers in a trusted context

Preserve the original email and examine From, Reply-To, Return-Path, Received and Authentication-Results fields. Authentication results must come from a trusted receiving system; attacker-supplied or otherwise untrusted headers are not authoritative.

SPF evaluates authorized sending hosts for the envelope domain. DKIM verifies a signature associated with a signing domain. DMARC checks alignment with the visible From domain. None of these verifies that the content of a payment request is legitimate.

Investigate genuine mailbox compromise

Authorized platform logs may show suspicious sign-ins, forwarding rules, delegated access or security changes. Availability depends on the platform, licensing, retention and collection authority. Missing logs are not proof that compromise did not occur.

Coordinate containment with administrators. Preserve relevant records, review access and follow the organization’s incident procedure. Do not attempt to access a mailbox without permission.

  • Separate claimed sender, envelope sender and authenticated domain.
  • Identify which receiving system supplied authentication results.
  • Check spelling, lookalike domains and changed Reply-To values.
  • Preserve authorized account logs and mailbox rules.
  • Keep domain observations separate from identity conclusions.

Sources and further reading

RFC 8601 — Authentication-Results headerRFC 7489 — DMARCFBI — Business email compromise
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.