{"id":42734,"date":"2021-09-07T15:08:17","date_gmt":"2021-09-07T15:08:17","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32619\/Outlook-Shows-Real-Contact-Info-For-Spoofed-IDNs.html"},"modified":"2021-09-07T15:08:17","modified_gmt":"2021-09-07T15:08:17","slug":"outlook-shows-real-contact-info-for-spoofed-idns","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/","title":{"rendered":"Outlook Shows Real Contact Info For Spoofed IDNs"},"content":{"rendered":"<figure class=\"intro-image intro-left\"><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/02\/microsoft-800x533.jpg\" alt=\"Shadowy figures stand beneath a Microsoft logo on a faux wood wall.\"><figcaption class=\"caption\"><\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"><a title=\"44 posters participating\" class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/information-technology\/2021\/09\/microsoft-outlook-shows-real-persons-contact-info-for-idn-phishing-emails\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">52<\/span> <span class=\"visually-hidden\"> with 44 posters participating<\/span> <\/a> <\/p>\n<div class=\"share-links\">\n<h4>Share this story<\/h4>\n<\/p><\/div>\n<\/aside>\n<p><!-- cache hit 1:single\/related:41970f11fcf65eb05154de87272db983 --><!-- empty --><\/p>\n<p>If you receive an email from <code>someone@arstechn\u0456ca.com<\/code>, is it really from someone at Ars? Most definitely not\u2014the domain in that email address is not the same <em>arstechnica.com<\/em>&nbsp;that you know. The &#8216;\u0456&#8217; character in there is from the Cyrillic script and not the Latin alphabet.<\/p>\n<p>This isn&#8217;t a novel problem, either. Up until a few years ago (but not anymore), modern browsers did not make any visible distinction when domains containing mixed character sets were typed into the address bar.<\/p>\n<p>And it turns out Microsoft Outlook is no exception, but the problem just got worse: emails originating from a lookalike domain in Outlook would show the contact card of a real person, who is actually registered to the legitimate domain, not the lookalike address.<\/p>\n<h2>Outlook shows real contact\u2019s info for spoofed IDN domains<\/h2>\n<p>This week, infosec professional and pentester&nbsp;<a href=\"https:\/\/twitter.com\/dobby1kenobi\" target=\"_blank\" rel=\"noopener\"><em>DobbyWanKenobi<\/em><\/a>&nbsp;demonstrated how they were able to trick the Address Book component of Microsoft Office to display a real person&#8217;s contact info for a spoofed sender email address by using IDNs.&nbsp;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Internationalized_domain_name\" target=\"_blank\" rel=\"noopener\">Internationalized Domain Names (IDNs)<\/a> are domains consisting of a mixed Unicode character set, such as letters from both Latin and Cyrillic alphabets that could make the domain appear identical to a regular ASCII domain.<\/p>\n<p>The concept of&nbsp;IDN was proposed in&nbsp;1996 to expand the domain name space to non-Latin languages and to deal with the aforementioned ambiguity of different characters that look identical (&#8220;homoglyphs&#8221;) to humans.&nbsp;IDNs can also easily be represented purely in ASCII format<em>\u2014<\/em>the &#8220;punycode&#8221; version of the domain, which leaves no room for ambiguity between two lookalike domains.<\/p>\n<p>For example, copy-pasting the lookalike &#8220;arstechn\u0456ca.com&#8221; into the address bar of the latest Chrome browser would immediately turn it into its punycode representation to prevent ambiguity:&nbsp;<em>xn--arstechnca-42i.com.&nbsp;<\/em>This does not happen when actual&nbsp;<em>arstechnica.com<\/em><em>\u2014<\/em>already in ASCII and without the Cyrillic &#8216;\u0456&#8217;, is typed into the address bar.&nbsp;Such visible distinction is necessary to protect the end users who may inadvertently land on imposter websites, used as part of phishing campaigns.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>But recently,&nbsp;<em>DobbyWanKenobi&nbsp;<\/em>found this wasn&#8217;t quite obvious with Microsoft Outlook for Windows. And the Address Book feature would make no distinction when showing the contact details of the person.<\/p>\n<p>&#8220;I recently discovered a vulnerability that affects the Address Book component of Microsoft Office for Windows that could allow anyone on the internet to spoof contact details of employees within an organization using an external look-alike Internationalized Domain Name (IDN),&#8221; wrote the pentester in a <a href=\"https:\/\/dobby1kenobi.medium.com\/lost-in-translation-222bbf00f2c\" target=\"_blank\" rel=\"noopener\">blog post<\/a>. &#8220;This means if a company\u2019s domain is &#8216;somecompany[.]com&#8217;, an attacker that registers an IDN such as &#8216;\u0455omecompany[.]com&#8217; (xn--omecompany-l2i[.]com) could take advantage of this bug and send convincing phishing emails to employees within &#8216;somecompany.com&#8217; that used Microsoft Outlook for Windows.&#8221;<\/p>\n<p>Coincidentally, the following day, another <a href=\"https:\/\/www.dionach.com\/blog\/spoofing-microsoft-outlook-contact\/\" target=\"_blank\" rel=\"noopener\">report<\/a> on the topic emerged from&nbsp;Mike Manzotti, a senior consultant at Dionach.&nbsp;For a contact created on Manzotti&#8217;s &#8220;onm\u00eccrosoft.com&#8221; domain (notice the <strong>\u00ec<\/strong>), Outlook displayed valid contact details of the person whose email address contained the real &#8220;onmicrosoft.com&#8221; domain.<\/p>\n<p>&#8220;In other words, the phishing email targets the user NestorW@&#8230;.onm<strong>\u00ec<\/strong>crosoft.com, however, valid Active Directory details and image of NestorW@&#8230;.onmicrosoft.com are displayed as if the email was coming from a trusted source,&#8221; says&nbsp;Manzotti.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/www.dionach.com\/wp-content\/uploads\/2021\/08\/NestorWilke.png\" width=\"403\" height=\"447\"><\/p>\n<p>Manzotti has traced the cause of the issue to Outlook not correctly validating email addresses in Multipurpose Internet Mail Extensions (MIME) headers.<\/p>\n<p>&#8220;When you send an HTML email you can specify the SMTP &#8216;mail from&#8217; address, and the Mime &#8216;from&#8217; address,&#8221; explains&nbsp;Manzotti.<\/p>\n<p>&#8220;This is because the MIME headers are encapsulated into the SMTP protocol. MIME is used for extending simple text messages, for example when sending HTML emails,&#8221; he explained with an illustration:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/www.dionach.com\/wp-content\/uploads\/2021\/08\/MimeMessage.png\" width=\"281\" height=\"322\"><\/p>\n<p>But, according to Manzotti, Microsoft Outlook for Office 365 does not correctly verify the punycode domain, letting an attacker impersonate any valid contact in the target organization.<\/p>\n<h2>IDN phishing: An old problem revived<\/h2>\n<p>The problem of IDN-based phishing websites&nbsp;gained the spotlight in 2017 when&nbsp;web application developer Xudong Zheng demonstrated how modern browsers, at the time, <a href=\"https:\/\/arstechnica.com\/information-technology\/2017\/04\/chrome-firefox-and-opera-users-beware-this-isnt-the-apple-com-you-want\/\" target=\"_blank\" rel=\"noopener\">failed to distinguish<\/a>&nbsp;his <em>\u0430pple.com<\/em>&nbsp;look-alike site (an IDN) from the real apple.com.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>Zheng was <a href=\"https:\/\/www.xudongz.com\/blog\/2017\/idn-phishing\/\" target=\"_blank\" rel=\"noopener\">concerned<\/a> that IDNs could be abused by attackers for various nefarious purposes such as phishing:<\/p>\n<blockquote>\n<p>From a security perspective, Unicode domains can be problematic because many Unicode characters are difficult to distinguish from common ASCII characters. It is possible to register domains such as &#8220;xn--pple-43d.com&#8221;, which is equivalent to &#8220;\u0430pple.com&#8221;. It may not be obvious at first glance, but &#8220;\u0430pple.com&#8221; uses the Cyrillic &#8220;\u0430&#8221; (U+0430) rather than the ASCII &#8220;a&#8221; (U+0061). This is known as a homograph attack.<\/p>\n<\/blockquote>\n<p>But the problem in Outlook is that for a phishing email sent from an IDN, the recipient may not only fail to distinguish between the spoofed email address and the real one but also see the contact card of a legitimate contact, therefore falling victim to the attack.<\/p>\n<p>It is unclear if Microsoft is inclined to fix the issue in Outlook at this time:<\/p>\n<p>&#8220;We&#8217;ve finished going over your case, but in this instance, it was decided that we will not be fixing this vulnerability in the current version,&#8221;&nbsp;a Microsoft staff member is seen telling&nbsp;<em>DobbyWanKenobi<\/em> in an email.<\/p>\n<p>&#8220;While spoofing could occur, the sender\u2019s identity cannot be trusted without a digital signature. The changes needed are likely to cause false positives and issues in other ways,&#8221; continued the email seen by Ars:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class src=\"https:\/\/miro.medium.com\/max\/3798\/1*0bu_AI_HygBzy2sRKO7_lA.png\" width=\"702\" height=\"119\"><\/p>\n<p>Microsoft has not responded to Ars&#8217; request for comment sent out in advance.<\/p>\n<p>Researchers have seen this vulnerability impacting both&nbsp;32-bit and 64-bit versions of the latest Microsoft Outlook for Microsoft 365&nbsp;versions, although it appears the issue was no longer reproducible on version 16.0.14228.20216 after Manzotti notified Microsoft.<\/p>\n<p>Oddly enough, Microsoft&#8217;s response to Manzotti maintained that the vulnerability will not be fixed. Additionally, Manzotti notes this type of phishing attack won&#8217;t succeed on&nbsp;Outlook Web Access (OWA).<\/p>\n<p>Taking advantage of security features such as &#8220;<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/native-external-sender-callouts-on-email-in-outlook\/ba-p\/2250098\" target=\"_blank\" rel=\"noopener\">external sender<\/a>&#8221; email warnings and email signing are a few steps organizations can take to deter spoofing attacks.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32619\/Outlook-Shows-Real-Contact-Info-For-Spoofed-IDNs.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":42735,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[9614],"class_list":["post-42734","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemicrosoftemailflawphish"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Outlook Shows Real Contact Info For Spoofed IDNs 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Outlook Shows Real Contact Info For Spoofed IDNs 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-07T15:08:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/outlook-shows-real-contact-info-for-spoofed-idns.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"533\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Outlook Shows Real Contact Info For Spoofed IDNs\",\"datePublished\":\"2021-09-07T15:08:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/\"},\"wordCount\":1064,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/outlook-shows-real-contact-info-for-spoofed-idns.jpg\",\"keywords\":[\"headline,microsoft,email,flaw,phish\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/\",\"name\":\"Outlook Shows Real Contact Info For Spoofed IDNs 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/outlook-shows-real-contact-info-for-spoofed-idns.jpg\",\"datePublished\":\"2021-09-07T15:08:17+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/outlook-shows-real-contact-info-for-spoofed-idns.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/outlook-shows-real-contact-info-for-spoofed-idns.jpg\",\"width\":800,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/outlook-shows-real-contact-info-for-spoofed-idns\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,microsoft,email,flaw,phish\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemicrosoftemailflawphish\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Outlook Shows Real Contact Info For Spoofed IDNs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Outlook Shows Real Contact Info For Spoofed IDNs 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/","og_locale":"en_US","og_type":"article","og_title":"Outlook Shows Real Contact Info For Spoofed IDNs 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-09-07T15:08:17+00:00","og_image":[{"width":800,"height":533,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/outlook-shows-real-contact-info-for-spoofed-idns.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Outlook Shows Real Contact Info For Spoofed IDNs","datePublished":"2021-09-07T15:08:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/"},"wordCount":1064,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/outlook-shows-real-contact-info-for-spoofed-idns.jpg","keywords":["headline,microsoft,email,flaw,phish"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/","url":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/","name":"Outlook Shows Real Contact Info For Spoofed IDNs 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/outlook-shows-real-contact-info-for-spoofed-idns.jpg","datePublished":"2021-09-07T15:08:17+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/outlook-shows-real-contact-info-for-spoofed-idns.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/outlook-shows-real-contact-info-for-spoofed-idns.jpg","width":800,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/outlook-shows-real-contact-info-for-spoofed-idns\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,microsoft,email,flaw,phish","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemicrosoftemailflawphish\/"},{"@type":"ListItem","position":3,"name":"Outlook Shows Real Contact Info For Spoofed IDNs"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42734","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=42734"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42734\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/42735"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=42734"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=42734"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=42734"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}