Tactic or Technique: Spoofing

Spoofing is when attackers falsify sender information to make a message look like it came from someone you trust by forging a real email address.
Messages like this often impersonate executives, IT support, or vendors and can lead to stolen credentials, wire fraud, or malware infections. When the source looks trustworthy, you're more likely to follow instructions, click a link, or open a file without hesitation.
Spoofing is especially effective when email authentication protocols like SPF, DKIM, and DMARC aren’t properly enforced. Without those protections, it becomes much easier for attackers to get past both technical filters and human judgment.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Navan
3d ago
Feb 9th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-navan-3573e9a8
Reconnaissance: Empty subject with mismatched reply-to from new sender
6d ago
Feb 6th, 2026
Sublime Security
/feeds/core/detection-rules/reconnaissance-empty-subject-with-mismatched-reply-to-from-new-sender-12f4bd45
Brand impersonation: DocuSign
7d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-4d29235c
Headers: Fake in-reply-to with wildcard sender and missing thread context
20d ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/headers-fake-in-reply-to-with-wildcard-sender-and-missing-thread-context-89da670a
Extortion / sextortion (untrusted sender)
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Vendor impersonation: Thread hijacking with typosquat domain
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Service Abuse: Nifty.com with impersonation
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-niftycom-with-impersonation-370cfdac
Headers: System account impersonation with empty sender address
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/headers-system-account-impersonation-with-empty-sender-address-887f7953
VIP impersonation: Fake thread with display name match, email mismatch
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/vip-impersonation-fake-thread-with-display-name-match-email-mismatch-11cc3e28
SPF temp error
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/spf-temp-error-2df7e839
Impersonation: SharePoint reply header anomaly
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/impersonation-sharepoint-reply-header-anomaly-78875848
Brand impersonation: State Farm
1mo ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-state-farm-bcf7eba0
Body: Embedded email headers indicative of thread hijacking/abuse
2mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/body-embedded-email-headers-indicative-of-thread-hijackingabuse-6e8eeebb
VIP Impersonation via Google Group relay with suspicious indicators
3mo ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
Brand impersonation: Survey request with credential theft indicators
3mo ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09
Headers: Outlook Express mailer
3mo ago
Nov 6th, 2025
Sublime Security
/feeds/core/detection-rules/headers-outlook-express-mailer-b7a698de
Attachment: ICS calendar with embedded file from internal sender with SPF failure
3mo ago
Oct 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-ics-calendar-with-embedded-file-from-internal-sender-with-spf-failure-d9ce9db8
VIP local_part impersonation from unsolicited sender
6mo ago
Aug 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-localpart-impersonation-from-unsolicited-sender-74035fdc
DocuSign impersonation via spoofed Intuit sender
6mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/docusign-impersonation-via-spoofed-intuit-sender-d437710b
Extortion / sextortion in attachment from untrusted sender
6mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c