Add Think Technology as a trusted source Email Spoofing in Microsoft 365 | TTA

Microsoft 365 spoofing emails and how to warn employees about bogus senders

microsoft office 365 logo

A scammer sends an email to your accounts team. The display name reads “Sarah from Finance” and everything looks right at a glance. But the sending address is an external Gmail account. Sarah has no idea. The money transfer goes through before anyone checks twice. This is display name spoofing, and it remains one of the most reliable tricks in a phisher’s kit.

Phishing is still the dominant entry point for cyber attacks on Australian businesses. The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) logged over 84,700 cybercrime reports in 2024-25, with the average self-reported cost per incident reaching $80,850. That is a 50% jump year-on-year. Email is the front door most attackers walk through first.

At TTA, we manage Microsoft 365 environments for Brisbane and South-East Queensland businesses every day. Display name spoofing comes up constantly. Here is what it is, why standard filters miss it, and the three approaches we use to protect staff.

What display name spoofing looks like

Spoofing is when the sender address shown to a recipient does not match the actual source of the email. Display name spoofing is a specific variation: the attacker keeps an external address but sets the visible “From” name to match someone inside your organisation. Most people check the name, not the address. That gap is all the attacker needs.

Microsoft’s threat intelligence team reported that phishing-as-a-service platforms such as Tycoon2FA are automating this at massive scale. In October 2025 alone, Microsoft Defender for Office 365 blocked over 13 million malicious emails linked to that single platform. Many of those emails appeared to come from inside the recipient’s own organisation. The lures included fake password resets, HR notifications, and shared document alerts.

For a 30-person Brisbane business, one convincing email to the right person can trigger a bank transfer, expose credentials, or open a door to ransomware. The technical sophistication matters less than the human moment when an employee trusts a display name without checking further.

Three ways to protect your team

There is no single fix that covers every spoofing scenario. What works is a layered approach. We apply these three options depending on the client’s setup, risk profile, and how much friction their team can handle.

Option 1: Banner warnings on all external email. A warning tag is added to the subject line or body of every email that arrives from outside the organisation. Something like: “CAUTION: This email originated externally.” It works because it is applied to every message, no configuration required per user.

The downside is familiarity. Once staff see the same warning on every email, including legitimate supplier messages, they stop reading it. Warning fatigue is real, and an ignored warning is no protection at all.

Option 2: Display name matching with a manual watchlist. A mail flow rule checks the display name of each incoming email against a list of names you specify. If an external sender uses a name that matches someone on your list, a warning is added to that specific email. This is more targeted than Option 1 and less noisy.

The trade-off is maintenance. You need to keep the list current as staff join, leave, or change roles. For businesses with high turnover, the admin overhead adds up quickly.

Option 3: User Impersonation Protection in Microsoft Defender for Office 365. This is the approach we recommend and apply proactively for clients on eligible Microsoft 365 plans. Microsoft’s built-in User Impersonation Protection compares incoming senders against a defined list of protected users (up to 350 per policy). When an external email uses a matching display name, Microsoft 365 can quarantine the message, redirect it to junk, or prepend a visible safety tip warning the recipient before they read further.

This option catches display name spoofing automatically, updates as Microsoft’s threat intelligence improves, and requires no manual tagging by staff. It also integrates with spoof intelligence, which evaluates whether the sending domain is authorised to send on behalf of the apparent sender.

The email authentication layer underneath

User Impersonation Protection works best when your domain’s email authentication records are correctly set up. The ACSC’s business email compromise guidance points to three DNS-based settings every organisation should have in place:

  • SPF (Sender Policy Framework): Specifies which mail servers are allowed to send email from your domain.
  • DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to outgoing messages so receiving servers can verify they haven’t been tampered with.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): Tells receiving servers what to do when SPF or DKIM fails, and reports back on who is sending email in your name.

Without these records in place, even good filtering tools have gaps. Microsoft’s own research found that organisations with complex mail routing and missing or loose DMARC enforcement are significantly more exposed to domain spoofing. Setting DMARC to “reject” or “quarantine” closes most of that gap. Our team checks these records as part of every IT audit we run.

Staff awareness still matters

Technical controls catch a lot. They don’t catch everything, and attackers keep finding new angles. The ACSC recommends that the best defence combines technical controls with regular employee training. Staff should know to check the actual email address (not just the display name) before acting on any request involving money, credentials, or sensitive information.

Practical habits that help:

  • Hover over the sender’s display name to reveal the actual address before replying or clicking.
  • Treat any unexpected request to transfer money or share login credentials as suspicious, regardless of who it appears to be from.
  • Use a second channel (phone call, Teams message) to verify urgent financial requests before acting.
  • Report suspicious emails through Outlook’s built-in “Report phishing” option, or forward to the ACSC at ReportCyber.

We cover email security awareness as part of the email security work we do for clients. The conversation about what to look for in a suspicious email is often the most practical thing we can do in a short session with a team.

A quick check for your business

Ask yourself these questions. If any answer is “no” or “not sure”, it is worth a conversation with your IT team or MSP:

  • Do you have SPF, DKIM, and DMARC records configured for your domain?
  • Is your DMARC policy set to “quarantine” or “reject” rather than just “none”?
  • Are key staff (finance, executives, HR) covered by User Impersonation Protection?
  • Do staff know how to check the actual sending address behind a display name?
  • Is there a clear process for verifying urgent financial requests out-of-band?

How do we get started?

If you want to know whether your Microsoft 365 environment has the right spoofing protections in place, we are happy to take a look. Our team works with businesses across Brisbane and South-East Queensland on exactly this kind of setup. Get in touch and we can walk you through what is configured, what is missing, and what to do next.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.