Test filesEmail › spoofed-display-name.eml

Sample EML file (spoofed display name)

A display name that reads as a trusted address while the real envelope address is something else entirely.

↓ Download spoofed-display-name.eml
Filenamespoofed-display-name.eml
FormatEML
Size410 bytes (410 bytes)
MIME typemessage/rfc822
SHA-2566146a3fbb9e0c1c2effc36c6bc8396a1faddc2a87b36aaa536d350049c706762
What this file catchesPhishing display. Any client that shows only the display name presents this as coming from [email protected], when the actual address is [email protected]. The single most common real-world phishing pattern.

Download & verify

curl -fsSL -o "spoofed-display-name.eml" "https://files.hexaqa.com/email/spoofed-display-name.eml"
curl -fsSL "https://files.hexaqa.com/email/spoofed-display-name.eml" | sha256sum # expect: 6146a3fbb9e0c1c2effc36c6bc8396a1faddc2a87b36aaa536d350049c706762

More email test files

missing-required-headers.emloutlook-message.msgplain-text.emlquoted-printable.emlthreaded-reply.emlunicode-headers.emlweb-archive.mhtwinmail-tnef.eml

← All Email files