Phishing glossary: 34 terms explained in plain language

By OpsinelPublished 8 min read

Short answer: Phishing is a scam in which an attacker pretends to be a trusted company, colleague or service to get a password, a payment or access to a computer. This glossary explains the 34 most common phishing and email security terms, from spear phishing and business email compromise to SPF, DKIM and DMARC, in one to three sentences each.

Security terms are often explained with more jargon. Here each one gets one to three plain sentences and, where we have one, a link to an article that explains it in depth. Every term has its own link, so you can share a single definition.

Types of attack

Phishing
A scam in which an attacker pretends to be a trusted company, colleague or service to get a password, a payment or access to a computer. It usually arrives by email, but also by text message, phone call or QR code. More: What is phishing.
Spear phishing
Phishing aimed at a specific person or company. The attacker uses real details, such as names, projects or suppliers, to make the message believable.
Whaling
Spear phishing aimed at senior managers, whose authority or access is especially valuable to an attacker.
Business email compromise (BEC)
A scam that uses a hijacked or spoofed business mailbox to ask for a payment or sensitive data. It often contains no link or attachment, only a convincing request. More: CEO fraud and invoice fraud.
CEO fraud
A type of BEC in which the scammer poses as the head of the company and asks an employee for an urgent, confidential transfer.
Invoice fraud
A fake or altered invoice, or a message about a supplier’s “new bank details”, so that a genuine payment goes to the scammer’s account. The defence is confirming new details by calling a number you already know.
Smishing
Phishing by text message or messaging app, for example an “undelivered parcel” with a link. More: Smishing: how to spot SMS scams.
Vishing
Phishing by phone: the caller pretends to be the bank, the police or IT support and asks for a code, a password or a transfer. More: Vishing: how to spot phone scams.
Quishing
Phishing through a QR code, on paper or in an email, that leads to a fake page. QR codes hide the address until they are scanned. More: QR code scams.
Clone phishing
A copy of a genuine email the victim received earlier, with the link or attachment swapped for a malicious one.
Adversary-in-the-middle (AiTM) phishing
A fake login page that passes everything to the real site as it happens, capturing both the password and the signed-in session. This lets the attacker get past some forms of two-factor authentication.
MFA fatigue
Sending sign-in approval requests again and again to someone whose password the attacker already has, hoping they approve one to make the notifications stop. Never approve a sign-in you did not start.
Social engineering
Manipulating people rather than systems: using trust, fear, urgency or a wish to help to get someone to act. Phishing is its most common form. More: Social engineering: how it works.
Pretexting
Inventing a believable story, such as a new IT contractor or a courier with a problem, to get information or access.
Credential harvesting
Collecting usernames and passwords through fake login pages. It is the most common goal of phishing emails.
Malware
Malicious software that steals data, spies on the user or takes control of a device. It often arrives as an email attachment or a download from a fake page.
Ransomware
Malware that encrypts a company’s files and demands payment to unlock them, often also threatening to publish stolen data. More: Ransomware: how to protect your business.

Email and domain security

Email spoofing
Sending an email with a forged sender address so that it looks as if it came from someone else. More: Email spoofing: how scammers send email in your name.
Display-name spoofing
Using a trusted name, such as your CEO’s, as the sender name while the actual address is a free mailbox. Mail apps often show only the name, so the address has to be checked.
Look-alike domain
A domain registered to resemble a real one, such as yourcompany-invoices.com or rn in place of m. Also called typosquatting. It can pass every technical check, so only an alert reader spots it.
SPF
Sender Policy Framework: a DNS record listing the servers allowed to send email for a domain. A domain has one SPF record, and it may trigger at most 10 further DNS lookups.
DKIM
DomainKeys Identified Mail: a digital signature added to every outgoing email and checked against a public key in the sender’s DNS. It proves the email came from the domain’s mail system and was not changed.
DMARC
A DNS record telling receivers what to do with email that uses your domain in the From field but fails SPF and DKIM, and where to send reports. Check your domain with the free SPF, DKIM and DMARC checker.
DMARC policy
The p= value of a DMARC record: none only monitors, quarantine sends failing email to spam, reject refuses it. Only quarantine and reject actually stop forged email.
MX record
A DNS record naming the servers that receive email for a domain. A domain without MX records does not receive email.
Email headers
The technical record at the top of every email: the servers it passed through and the results of the SPF, DKIM and DMARC checks (the Authentication-Results line). In Gmail they are under “Show original”.

Protection and training

Two-factor authentication (2FA)
Signing in with a second step, such as an app code or a security key, on top of the password, so that a stolen password alone is not enough. Also called multi-factor authentication (MFA). More: Two-factor authentication.
Passkey
A way to sign in without a password, using a cryptographic key stored on your device. It only works on the genuine site, so it cannot be typed into a fake page.
Password manager
An app that creates and stores a separate strong password for every account, and fills it in only on the right site. More: How to create a strong password.
Phishing simulation
A safe, realistic phishing email sent to employees to practise spotting scams. Whoever clicks learns straight away what they missed. More: What is a phishing simulation.
Click rate
The share of recipients who clicked the link in a phishing simulation. It is only meaningful when compared across tests of similar difficulty. More: Phishing test for employees.
Security awareness training
Regular training that teaches employees to recognise and report scams, usually short lessons combined with phishing simulations. More: How to train employees to spot scams.
Incident response
The agreed steps after a security event: who is told, who changes passwords, who contacts the bank. Speed matters more than blame. More: What to do after clicking a phishing link.
Data breach
An incident in which personal or company data is exposed to someone who should not have it, for example leaked passwords from a hacked service. More: Data breach: what to do.

Try it yourself

Can scammers send email in your name?

A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.

Could you spot a phishing email?

10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.

Take the phishing quiz

Frequently asked questions

What is the difference between phishing and spear phishing?

Phishing is sent to many people at once with a generic story. Spear phishing targets a specific person or company and uses real details, such as names or suppliers, so it is harder to spot.

What is the difference between spoofing and phishing?

Spoofing is forging the sender, for example writing your company’s address in the From field. Phishing is the scam itself: what the message tries to get you to do. A phishing email may or may not be spoofed.

Are smishing, vishing and quishing types of phishing?

Yes. They are the same scam through a different channel: smishing by text message, vishing by phone and quishing through a QR code.

Sources and further reading

Public guidance from security agencies and standards bodies.

From theory to practice

A phishing simulation lets your employees practise: they get a realistic email and, if they click, a short lesson straight away. Create an account and see sample data straight away.