Clone phishing is a phishing technique where an attacker copies a legitimate, previously sent email almost exactly, then swaps a link or attachment for a malicious one and resends it, exploiting the trust already built by the original message. Unlike most phishing, which relies on generic urgency or an unfamiliar sender to create pressure, clone phishing relies on familiarity. The email looks like something the recipient has already seen, which is exactly why it works. This guide covers how clone phishing works, how it differs from regular phishing, the warning signs that survive even a convincing copy, and what actually catches it.
Key Takeaways
- Clone phishing copies a real, previously sent email almost exactly, then swaps the link or attachment for a malicious one, exploiting trust the recipient already has.
- Unlike regular phishing, clone phishing rarely has visible red flags like typos or an unfamiliar sender, since it starts from an authentic message.
- DKIM replay attacks are a more advanced variant where the attacker resends a genuinely signed email, allowing the message to pass standard DKIM authentication checks.
- Authentication protocols (SPF, DKIM, DMARC) alone do not catch every clone phishing variant.
- Detection needs historical context on real senders and threads, which is why API-based email security can catch what authentication checks miss.
What Is Clone Phishing?
Clone phishing is a phishing technique that replicates the look, content, and format of a real, previously sent email, then substitutes a malicious link or attachment for the original. Because the message starts from something genuine, often a newsletter, a shipping confirmation, or a document a colleague actually sent, it skips past the usual red flags recipients are trained to watch for. The attacker is not fabricating trust from nothing. They are borrowing trust that already exists.
How Clone Phishing Works
A typical clone phishing attack follows a consistent pattern. The attacker first obtains a real email, either by breaching an inbox, intercepting a message in transit, or simply observing a public email like a newsletter signup confirmation. Hackers then recreate the branding, formatting, and sender details as closely as possible, and finally substitute the content: a link redirected to a fake website built to look like the legitimate site and harvest credentials, or a malicious attachment swapped in for the real one. The email is then sent, often claiming to be a resend, an updated version, or a correction to the original.
Because the message shares nearly all of its content with something already delivered, it can slip past email filters that only check whether a sender or domain is on a blocklist. The individual elements, sender name, formatting, even most of the text, all look legitimate, which is exactly what filters built around known-bad signals are not designed to catch.
DKIM replay attacks are a more advanced variant worth understanding on their own. In a standard clone phishing attack, the attacker fabricates a copy of a real email. In a DKIM replay attack, the attacker does not need to fabricate anything: they obtain a genuinely DKIM-signed email, often by subscribing to a newsletter or triggering an automated system message, and simply resend that authentic, cryptographically signed message to new targets. Because the original signature is valid, the replayed email passes DKIM authentication checks at the receiving server. This is why authentication protocols like SPF, DKIM, and DMARC, while important, do not catch every clone phishing variant on their own. A message can pass every authentication check and still be part of an attack.
Clone Phishing vs. Regular Phishing
Regular phishing is often generic and carries visible flaws: spelling errors, an unfamiliar sender, or formatting that does not quite match the brand it claims to be. Clone phishing starts from a real, legitimate email, so those usual tells are largely absent. The formatting is correct because it was copied from a real email. The sender name is familiar because it is the same name the recipient has seen before.
It is also worth distinguishing clone phishing from spear phishing. Spear phishing is personalized to a specific target using details an attacker has gathered about them, while clone phishing borrows an entire message that already exists and alters only what it needs to. Both are more convincing than generic phishing, but for different reasons, one through research, the other through familiarity.
Warning Signs of a Clone Phishing Email
A few details in an otherwise convincing, suspicious email tend to survive even a good copy:
- A sender address with subtle misspellings or a different domain than the original sender's real address, even when the display name looks correct
- Unexpected urgency layered onto an otherwise familiar message, such as "please resend your payment details immediately"
- Links that do not match the expected destination when hovered over, even if the visible link text looks right
- A resend, correction, or "updated" framing for a message the recipient does not remember expecting an update to
- A request for information the original message never asked for
How to Prevent and Detect Clone Phishing
Build the habit of checking sender domains and hovering links, especially on messages that claim to be a resend or correction. This catches a meaningful share of clone phishing attempts, but it is not a complete defense on its own, particularly against DKIM replay attacks where the message is technically authentic.
Detection needs to go beyond authentication protocols alone. Because a DKIM replay attack passes SPF, DKIM, and DMARC checks, detection has to look at context: whether the email fits the sender's normal pattern, whether the request is consistent with prior communication, and whether the destination of a link matches what the message claims. The stakes of getting this wrong are real: credentials taken through a successful clone phishing attack can lead to unauthorized access, financial fraud, or identity theft well beyond the original message. See email security and stopping sophisticated email attacks.
How Material Stops Clone Phishing
Material connects to the mailbox by API, which gives it historical context on real senders and real threads that a static filter does not have. That context makes it possible to recognize when a message diverges from a sender's established pattern, even when the message itself is a convincing, or even authentically signed, copy. If a clone phishing attempt does reach a user, Material's automated user-report triage means one confirmed report protects the rest of the organization immediately, spreading protection across the entire user base within seconds rather than requiring every employee to independently spot the same threat. See automated user report response and stopping business email compromise and vendor email compromise.
Catch Clone Phishing That Authentication Checks Miss
Clone phishing is effective precisely because it does not look like an attack. It looks like an email the recipient has already trusted once. Material's approach to cybersecurity is built around that gap: real sender history, real thread patterns, and organization-wide signal, to catch clone phishing attempts that pass authentication checks and slip past users trained on typical phishing red flags. To see where your organization's exposure stands, run the free Workspace Security Scorecard, or try Material risk free.
Clone Phishing FAQs
What is clone phishing?
Clone phishing is a phishing technique where an attacker copies a legitimate, previously sent email almost exactly, then swaps a link or attachment for a malicious one and resends it. It relies on the trust the recipient already placed in the original message, rather than fabricating trust from an unfamiliar sender.
How is clone phishing different from regular phishing?
Regular phishing is typically generic and carries visible red flags, like spelling errors or an unfamiliar sender. Clone phishing starts from a real message the recipient has already seen, so the formatting, sender name, and tone all look correct, which removes the usual warning signs.
What are the warning signs of a clone phishing email?
Watch for a sender address with subtle misspellings, unexpected urgency added to an otherwise familiar message, links that do not match their expected destination on hover, and a resend or "updated" framing for something you were not expecting an update to.
Can clone phishing bypass email authentication like DKIM?
Yes, in a variant called a DKIM replay attack. Instead of fabricating a copy, the attacker obtains a genuinely DKIM-signed email, such as a newsletter confirmation, and resends that authentic message to new targets. Because the signature is real, the message passes DKIM authentication checks at the receiving server.
How does Material detect clone phishing that authentication checks miss?
Material connects to the mailbox by API, giving it historical context on real senders and threads rather than relying on authentication checks alone. This makes it possible to recognize when a message diverges from a sender's established pattern, even when the message passes SPF, DKIM, and DMARC. See email security.
Does Material use AI to catch clone phishing attempts?
Yes. Material uses behavioral and contextual detection to identify clone phishing, including DKIM replay attempts that pass standard authentication checks. Detection is based on patterns in sender history and message context rather than protocol checks alone, and one confirmed report protects the rest of the organization automatically.

