Definition
Email phishing is a form of social engineering where attackers send deceptive messages designed to trick recipients into revealing sensitive information, installing malware, or taking actions that compromise security. Phishing emails typically impersonate trusted brands, financial institutions, or internal corporate communications, using urgent language and fabricated scenarios to provoke immediate action. The FBI's Internet Crime Complaint Center reported 298,000 phishing complaints in 2023 with adjusted losses exceeding $2.7 billion. Phishing accounts for approximately 90 per cent of all data breaches according to the 2024 Verizon Data Breach Investigations Report.
Phishing creates a significant problem for legitimate email marketers because the same authentication technologies used to stop spoofed phishing emails — SPF, DKIM, and DMARC — are also used by legitimate senders. When mailbox providers deploy aggressive phishing filters, legitimate marketing emails can be caught in false positive classifications, particularly for brands in highly targeted sectors such as banking, payments, and e-commerce. A 2024 Red Sift study found that 28 per cent of legitimate banking marketing emails were initially flagged as suspicious by AI-based phishing detectors, requiring senders to implement additional whitelisting and reputation management strategies.
The impact of phishing extends beyond direct fraud losses. When a domain is used in phishing campaigns, even if the attacker is using a lookalike domain rather than the actual domain, mailbox providers begin associating the brand with phishing activity. This association depresses sender reputation scores and reduces inbox placement rates for legitimate marketing campaigns. According to a 2023 Validity report, brands in the financial services sector experienced inbox placement rates averaging 87 per cent compared to the cross-industry average of 93 per cent, with phishing associations cited as the primary cause of the discrepancy.
Best Practices
Implement DMARC enforcement with a reject policy to prevent exact-domain spoofing of your marketing and corporate domains. This is the single most effective technical control against phishing that uses your brand name in the From address. Google and Yahoo now require DMARC enforcement for bulk senders, and many mailbox providers use DMARC policy as a direct signal in their phishing classification algorithms.
Monitor lookalike and cousin domain registrations using domain monitoring services or your registrar's brand protection features. Phishing campaigns increasingly use domains such as yourbrand-security.com or yourbrand-support.net that visually resemble your actual domain. When discovered, issue takedown requests to the registrar and report the domain to Google Safe Browsing and Microsoft Defender for brand protection.
Educate your subscribers about how your legitimate marketing emails will appear, including the specific From address, subject line conventions, and what you will never ask for via email. Publish this guidance on your preference centre and include periodic reminders in your newsletters advising subscribers to verify the authenticity of unexpected messages claiming to be from your organisation.
Work with your ESP to implement feedback loops and abuse reporting mechanisms that alert you when recipients mark your email as phishing rather than spam. These reports provide early warning when attackers are using your brand identity in phishing campaigns, allowing you to take pre-emptive action before mailbox providers adjust their trust algorithms.
Avoid sending marketing emails that resemble common phishing triggers — such as urgent password reset prompts, security alert notifications, or account verification requests — unless the email is genuinely transactional and expected by the recipient. If you must send security-themed marketing communications, use a separate dedicated sending domain and IP pool to avoid contaminating your primary marketing reputation.
Related Glossary Terms
Bounce Classification
Bounce classification uses SMTP codes (550, 551, 552, 553, 554, 450, 451, 452) and enhanced status codes to categorise permanent and transient delivery failures.
DMARC Alignment
DMARC identifier alignment determines whether the domain in the From header matches the domains used in SPF and DKIM authentication. Strict or relaxed.
DMARC Policy Tags
DMARC DNS record tags including v, p, sp, rua, ruf, pct, adkim, aspf, fo, rf, and ri control authentication policy, reporting, and alignment enforcement.
Email Active Subscriber
An active email subscriber has opened or clicked an email within a defined recency period, typically 30-90 days by industry. Active subscriber rate of 40-60% is typical for healthy email lists.
Email BIMI VMC
BIMI Verified Mark Certificate (VMC) certifies brand logo ownership for display in supporting email clients. VMCs cost £1,500-2,000+ per year per logo and require DMARC reject or quarantine policy plus SVG logo format.
Email Blacklist
An email blacklist (DNSBL) is a real-time database of IP addresses or domains known for sending spam or unwanted email.
Frequently Asked Questions
When mailbox providers detect phishing activity using a brand identity, they may apply stricter filtering rules to all emails from that brand, including legitimate marketing campaigns. This can reduce inbox placement rates by 10 to 20 percentage points until the provider's algorithms are retrained.
Spoofing is the technical act of forging a sender address, while phishing is the social engineering goal of the message. Not all spoofed emails are phishing, but most phishing emails use spoofing techniques. Phishing may also use legitimate sending infrastructure through compromised accounts.
Authenticate all messages with SPF, DKIM, and DMARC. Maintain consistent sending volumes and patterns. Avoid using language, formatting, or URLs that resemble email security alerts. Monitor your sender reputation using Google Postmaster Tools and Microsoft SNDS.
Report the phishing emails to the Anti-Phishing Working Group, Google Safe Browsing, and Microsoft. Issue takedown requests for any lookalike domains. Send a notification to your subscribers through a non-email channel if possible, and add a warning to your website.
These protocols prevent exact-domain spoofing but do not prevent phishing sent from compromised accounts, lookalike domains, or domains that have not implemented authentication. They are necessary but not sufficient for comprehensive phishing prevention.