Forum Discussion

sumo83's avatar
sumo83
Iron Contributor
Jun 24, 2024
Solved

Display Name Spoofing very often recently - how to prevent it

Hi experts,   recently, I have noticed increase in emails that tries to impersonate sender  (Display Name Spoofing). The Display name shows a real user from our organization, however the sender ema...
  • JeremyTBradshaw's avatar
    Sep 05, 2025

    For DisplayName spoofing you definitely want User Impersonation protection, and you can only protect up to 350 users (per Anti-Phish policy, not sure if/how well it scales up if you try to do as many policies as necessary to cover all users).  User Impersonation Protection

    You'll get more than just DisplayName spoofing protection.  Even similar email addresses will be detected.  You will likely need to then add some Trusted Senders as well, to avoid certain external senders being falsely detected as impersonation attemps.  Trusted Senders and Domains

    To close the loop on Domain Impersonation - that is focusing on the domain portion of the email address, so it is not going to cover you for DisplayName spoofs.  Things like M1crosoft.com would be detected as impersonating Microsoft.com.

Resources