Phishing
A fraudulent message designed to trick someone into handing over credentials, approving a login, or opening something malicious.
Phishing remains one of the most common ways attackers get their first foothold, because it targets the one component you cannot patch. The modern version rarely looks like the badly spelled bank email of a decade ago. It looks like a document share from a colleague, a voicemail notification, or an invoice from a supplier whose mailbox has already been compromised.
Training helps but never gets to zero, so the technical controls carry the weight: link and attachment inspection at the gateway, phishing-resistant MFA so a stolen password is not enough, and conditional access so a session from an unexpected location gets challenged.
Where this comes up
Phishing sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.
Measure this on your own domain
Our free email authentication checker reads this record for any domain over public DNS, grades what it finds, and gives you the exact record to publish if it is wrong. No sign-up.
Check your domain →