Comprehensive List of User Deception Techniques in Emails

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Veit, Maxime, Mossano, Mattia, Länge, Tobias, Volkamer, Melanie
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910106022576128
author Veit, Maxime
Mossano, Mattia
Länge, Tobias
Volkamer, Melanie
author_facet Veit, Maxime
Mossano, Mattia
Länge, Tobias
Volkamer, Melanie
contents Email remains a central communication medium, yet its long-standing design and interface conventions continue to enable deceptive attacks. This research note presents a structured list of 42 email-based deception techniques, documented with 64 concrete example implementations, organized around the sender, link, and attachment security indicators as well as techniques targeting the email rendering environment. Building on a prior systematic literature review, we consolidate previously reported techniques with newly developed example implementations and introduce novel deception techniques identified through our own examination. Rather than assessing effectiveness or real-world severity, each entry explains the underlying mechanism in isolation, separating the high-level deception goal from its concrete technical implementation. The documented techniques serve as modular building blocks and a structured reference for future work on countermeasures across infrastructure, email client design, and security awareness, supporting researchers as well as developers, operators, and designers working in these areas.
format Preprint
id arxiv_https___arxiv_org_abs_2604_04926
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Comprehensive List of User Deception Techniques in Emails
Veit, Maxime
Mossano, Mattia
Länge, Tobias
Volkamer, Melanie
Cryptography and Security
Human-Computer Interaction
Email remains a central communication medium, yet its long-standing design and interface conventions continue to enable deceptive attacks. This research note presents a structured list of 42 email-based deception techniques, documented with 64 concrete example implementations, organized around the sender, link, and attachment security indicators as well as techniques targeting the email rendering environment. Building on a prior systematic literature review, we consolidate previously reported techniques with newly developed example implementations and introduce novel deception techniques identified through our own examination. Rather than assessing effectiveness or real-world severity, each entry explains the underlying mechanism in isolation, separating the high-level deception goal from its concrete technical implementation. The documented techniques serve as modular building blocks and a structured reference for future work on countermeasures across infrastructure, email client design, and security awareness, supporting researchers as well as developers, operators, and designers working in these areas.
title Comprehensive List of User Deception Techniques in Emails
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2604.04926