---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for Email Domain Spoofing Detection

# Playbook for Email Domain Spoofing Detection {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This playbook helps with the early stage triage of user-reported phishing submissions by alerting the analyst to the possibility of a look-alike domain in the Phisher's email address.

The Email Domain Spoofing Detection playbook looks to find a similarity match between the Phisher's sender email domain with a trusted domain name exists in the observable repository. When a spoofed sender email domain match has been
identified by the playbook, the analysts are alerted with a tag.

The workflow is created based on an existing playbook, which provides a consistent and efficient approach for incident investigation. Each decision point in the playbook has been converted into an outcome driven task and flow changes
direction based on the outcome of such tasks.
* **[Set up the Email Spoof Detection playbook](https://servicenow-prod.fluidtopics.net/EfGjb66_PutHbb7Gzow8ZA)**   
  Use the following steps to set up the Email Spoof Detection playbook.
* **[Use the Email Domain Spoofing Detection playbook](https://servicenow-prod.fluidtopics.net/4Cb25_crskJ0MnQB58qe7g)**   
  Use this playbook to find a similarity match between the Phisher's sender email domain with a trusted domain name exists in the observable repository. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Email Domain Spoofing Detection playbook.

