Skip to content

Display name spoofing: the attack DMARC does not stop

An attacker can send from any free mailbox with your CEO's name in the display field. Why authentication cannot stop it and what actually helps.

Koltrix Team4 min read
A fishing lure hanging from a rod
Photo by Stötzer Balázs on Unsplash
On this page(7 sections)
  1. What a display name is
  2. Why SPF, DKIM and DMARC cannot help
  3. Common variations
  4. Defenses that actually work
  5. 1. Make the real address visible
  6. 2. Filter on display names that match your people
  7. 3. Watch for Reply-To mismatches
  8. 4. Verify requests out of band
  9. 5. Train for the specific pattern
  10. What your organization can do for others
  11. A quick review checklist
  12. Key takeaways

The attacker does not need your domain. They create a free mailbox, set the display name to your CEO's name, and email your finance team.

Every authentication check passes, because the message is exactly what it claims to be at the protocol level: mail from a free mailbox the attacker controls.

What a display name is

An email From header has two parts: an optional display name and the actual address.

From: "Jordan Lee" <[email protected]>

Mail clients show the display name prominently. Many mobile clients show only the display name in the message list, and reveal the address only when you tap on it. People read "Jordan Lee," recognize their CEO, and act.

The address part, freemail.example, belongs to a legitimate free email provider. That provider signs the message with DKIM, its servers pass SPF, and DMARC passes for freemail.example. Nothing in the authentication chain is false.

Why SPF, DKIM and DMARC cannot help

Email authentication answers one question: is this message really from the domain in the From address? For display name spoofing, the honest answer is yes. The deception lives entirely in the human-readable label, which none of these standards evaluates.

That distinction matters when people ask why they still receive "CEO fraud" emails after reaching DMARC p=reject. DMARC stops attackers from using @example.com in the From address. It does not stop them from using the words "Example Inc." or your executives' names in front of somebody else's address.

Common variations

Variation What the user sees What is really there
Executive impersonation "Jordan Lee" A free mailbox address
Brand impersonation "Example Billing Team" An unrelated domain
Address in the display name "[email protected]" <[email protected]>
Reply-To redirection A legitimate-looking sender Replies go to an attacker address
Vendor impersonation "Acme Supplies Accounts" A new free mailbox

The third row is especially effective: the display name itself contains a plausible email address, so a quick glance shows your domain even though the actual address is something else entirely.

Defenses that actually work

No single control solves this. Effective programs stack several.

1. Make the real address visible

Configure mail clients, where you control them, to show the full sender address rather than only the display name. Many organizations add an external sender banner, a short notice inserted at the top of messages from outside the organization, such as "This message came from outside your organization." It is crude, but it gives people a moment to notice that their "CEO" is writing from outside.

Banners lose effectiveness when every message has one, so some teams show them only for messages whose display name matches an internal person but whose address is external.

2. Filter on display names that match your people

Many email security gateways and some mailbox platforms support rules that flag or quarantine inbound mail where:

  • The display name matches an employee or executive name, and
  • The sending address is not in your domain or an approved list.

Expect false positives: a person with the same name at another company, or an executive's personal account. Start in tagging mode and tune before quarantining.

3. Watch for Reply-To mismatches

Attackers often set a Reply-To header pointing to a different address so the conversation moves somewhere they control. A message from one address with replies directed to another, unrelated address is a strong signal, particularly for first-time correspondents.

4. Verify requests out of band

Display name spoofing is usually a means to an end: a wire transfer, a gift card purchase, a change to payroll bank details, or sensitive documents. Process controls beat filters here:

  • Payment and banking changes are confirmed by phone, using a number from your own records, never one in the email.
  • Unusual requests from executives can always be checked through a second channel without anyone being embarrassed.
  • Gift card requests by email are treated as fraud by default.

5. Train for the specific pattern

Generic phishing training talks about suspicious links. Display name spoofing often has no link at all, just a short, urgent, plausible request: "Are you at your desk? I need a quick favor." Show staff real examples of that style and explain how to reveal the actual address on their own devices.

What your organization can do for others

You cannot stop attackers from typing your company name into a display name. You can make your genuine mail easier to recognize and the fake mail easier to spot:

  • Send consistently. Use the same From addresses and display names for each kind of mail, so recipients learn what normal looks like.
  • Authenticate everything and publish DMARC at enforcement, so at least exact-domain spoofing fails.
  • Consider BIMI. At mailbox providers that support it, a verified logo next to your authenticated mail can make unauthenticated imitations look different. It helps recipients only if they notice the absence of the logo, so treat it as a modest signal, not a defense.
  • Tell customers how you contact them. A support page stating which addresses you send from, and that you never ask for passwords or payment changes by email, gives people something to check against.

A quick review checklist

  • Mail clients show full sender addresses where configurable.
  • External sender banners or targeted warnings are in place.
  • Inbound rules flag external mail using internal people's names.
  • Reply-To mismatches on first-contact mail are flagged.
  • Payment and banking changes require out-of-band verification.
  • Training covers link-free, request-only impersonation.
  • Your own outbound mail uses consistent names and addresses, with DMARC at enforcement.

Key takeaways

  • Display name spoofing puts a trusted name in front of an attacker-controlled address, and authentication passes because the address is genuine.
  • DMARC protects your domain, not your name or your brand's words.
  • Effective defenses combine visibility of the real address, name-matching filters, Reply-To checks and out-of-band verification.
  • Process controls around payments stop the attacks that filters miss.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn