Indicators, not proof
SPF, DKIM and DMARC answer whether a message really comes from the domain in the sender address. Against a phishing message sent from the attacker's own, properly authenticated domain they do nothing — and that is how many attacks work: the domain is genuine, it just is not the bank's. The deception sits in the display name, the reply address and the links.
The report therefore looks for traits that phishing typically carries. Each of them can have an innocent reason. They are indicators, and they do not affect the Security Score.
What AnalyzeMy.Email checks
Sender
- Foreign address in the display name (
high) — the name in front of the actual address itself contains an email address whose organizational domain does not match the real sender. Example:"service@bank.example" <info@other-domain.example>. Many mail clients show only the name. - Foreign domain in the display name (
medium) — the name mentions another organization's domain, such as “PayPal.com Service” on a message from an entirely different domain. This is only checked when no foreign address was found, and only for real domain names per the Public Suffix List — a version number like “1.2” does not count.
Reply address
- Reply-To at a freemail provider (
medium) — the sender is not a freemail address, yet replies go to a mailbox at Gmail, Outlook.com, Yahoo, GMX, Web.de or another large freemail service. The classic pattern of invoice and CEO fraud: the message arrives looking credible, the reply lands with the attacker. A Reply-To domain that differs in general is additionally reported by the header analysis.
Links
- Target disguised with @ (
high) — inhttps://bank.example@other-domain.example/everything before the@is just a user name. The actual target is the domain after it. - Link to an IP address (
medium) — legitimate senders link to domains, not to bare IPv4 or IPv6 addresses. - Link text shows a different domain than the target (
medium) — in the HTML part, the visible link text is a domain name, but the link leads to a different organization. The comparison is on the organizational domain per the Public Suffix List:www.example.comandshop.example.comcount as the same,example.comandexample-login.netdo not.
The checks for @ and IP addresses run over up to 50 http and https links in the message. The overall verdict follows the most severe indicator.
When a hit is harmless
- Click tracking in newsletters. Sending services rewrite every link to their own tracking domain in order to count clicks. The text then shows
yourshop.comwhile the target is a host of the sending service — “link text shows a different domain” is the expected result here, not an attack. In a message from your bank or a parcel service, the same finding is a strong warning sign. - Reply-To to a freemail mailbox happens at small businesses that route replies there on purpose. It remains unusual all the same.
- A domain in the display name can be a brand name written like a domain, or a marketplace sending on behalf of a merchant.
For senders this means: to avoid such indicators, link to your own domains — many sending services offer a tracking subdomain under your own domain for this — and set Reply-To to an address of your own organization.
What this check does not cover
- Look-alike domains, where a Latin “a” has been swapped for a Cyrillic one, for instance, are caught by homograph detection.
- Listed link domains are checked by the URL blacklist check.
- Dead links and redirect chains are shown by the link check.
- Forged sender domains are stopped by DMARC — provided the domain publishes an enforcing policy.
- The wording itself — urgency, threats, payment demands — is not evaluated.