Knowledge / identity network acsc-glossary

Spoofing

A message or identity dressed as a trusted source. Email, SMS, caller ID, and websites all do this cheaply.

PHISHING / identity abuse, not a malware class01Lure02Landing03Capture04ReuseControls: phishing-resistant MFA, reporting, mail auth, drills.

Spoofing is making a communication look like it came from someone you already trust. A lookalike vendor email, a cloned login page, a caller ID that says the bank. The content is the tell; the From line is not evidence.

Mail authentication (SPF, DKIM, DMARC) makes domain spoofing harder. Browser warnings, known-good URLs, and a callback on a number you already have beat 'it looked official'.

Fact source: ASD's ACSC glossary.