Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› How should security teams detect TOAD phishing when…
Threats, Abuse & Incident Response

How should security teams detect TOAD phishing when emails pass SPF, DKIM, and DMARC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Threats, Abuse & Incident Response

Detect TOAD campaigns with behavioural signals rather than message content alone. Teams should compare sender-recipient history, brand-recipient pairing, callback-number usage, and burst patterns across many recipients. The key is to correlate the email with the expected communication context, because authenticated messages can still be used to drive credential theft through a voice callback.

How TOAD Detection Has to Work When Authentication Checks Still Pass

TOAD, telephone-oriented attack delivery, succeeds because the email is only the opening move. A message can clear SPF, DKIM, and DMARC and still be malicious if it is used to prompt a phone call that lands a victim with a convincing fraud script. Security teams should therefore treat mail authentication as necessary hygiene, not as proof of legitimacy, and look for the behavioural pattern around the message, not just the message itself.

That changes detection from content filtering to context analysis. The useful question is not whether the sender domain authenticated, but whether the communication makes sense for that sender, that recipient, and that moment. In practice, that means comparing the sender-recipient relationship, the brand being impersonated, whether a callback number is present, and whether the same lure is being pushed in bursts across many mailboxes.

Detection gets stronger when those signals are combined. A single unexpected invoice message may be noise; the same invoice theme sent to multiple finance users, from an authenticated domain with a callback number that routes outside normal business channels, is a much better indicator of TOAD activity. Correlation matters because the adversary is exploiting trust in the voice channel after the email has already bypassed standard authentication controls.

What Behavioural Signals Actually Separate TOAD From Legitimate Mail

The most useful signal is sender-recipient history. If a sender that has never contacted a recipient before suddenly requests a phone call, payment verification, or immediate action, that deserves more weight than a properly aligned header block. Brand-recipient pairing is the next check, since attackers often borrow a trusted brand that has no normal business relationship with the target.

Callback-number usage is especially important. TOAD often includes a number that is not a routine corporate contact point, or one that diverts the victim into an attacker-controlled conversation. Teams should also look for multi-recipient bursts, because these campaigns are usually industrialized: the same script is sent broadly and then individualized by the voice operator once someone responds.

These are detection features, not standalone proof. A legitimate business could still send a new contact number or a one-time outreach campaign. The value comes from scoring several weak indicators together and comparing them against expected communication context, such as established vendors, routine invoice workflows, and known payment validation procedures.

Why Mail Authentication Alone Is the Wrong Confidence Signal

SPF, DKIM, and DMARC tell you that a message was sent from infrastructure permitted to use the domain, not that the sender is trustworthy in the business sense. Attackers can compromise legitimate sending platforms, abuse third-party mail services, or simply use authenticated messages to initiate a separate social-engineering step. That is why TOAD can survive even when the email layer looks clean.

This is also where mailbox and recipient context matter. If a campaign targets users who normally approve payments, support requests, or account changes, the email should be evaluated against the workflow that those users actually follow. A compliant authentication result should reduce suspicion about spoofing, but it should not suppress scrutiny of unusual urgency, off-channel contact, or requests that redirect the user into a phone-based fraud sequence.

The right operating model is layered detection: authentication to reduce classic spoofing, contextual analysis to catch trusted-domain abuse, and downstream controls to prevent the phone callback from becoming the point of compromise.

Practical Detection Workflows for Security Operations

Teams usually get better results when they hunt for TOAD across mail telemetry rather than waiting for one reported message. The Email Identity and BEC Guide is useful here because it ties SPF, DKIM, and DMARC to the broader problem of email impersonation and payment fraud, which is the right frame for TOAD hunting.

The Mailchimp breach 2022 is a reminder that trusted sending paths and exposed audience data can support phishing at scale, so bulk delivery patterns and brand abuse deserve attention even when messages appear authenticated. For defenders, that means building detections around campaign shape, not just per-message verdicts.

Where callback-driven fraud is part of the pattern, mail hunting should feed case management quickly enough for finance, service desk, or fraud teams to warn users before a voice callback succeeds. The TruffleNet stolen AWS keys campaign 2025 shows how business email compromise can scale once an attacker can validate access and push a convincing invoice, which is a good model for why campaign correlation matters.

Risk and Threat Considerations

TOAD is risky because it bypasses the assumption that authenticated mail is safe. Once the attacker has a trusted-looking message in the inbox, the phone call becomes the real attack path, where urgency, authority, and live conversation can overcome normal user caution. That makes this technique especially effective against payment, procurement, and support workflows.

Failure mechanism: The defender overweights SPF, DKIM, and DMARC, while the attacker uses a legitimate-looking email to trigger an off-channel voice interaction that is not covered by mail authentication controls.

Impact: Users can be manipulated into payment diversion, credential disclosure, or account actions that look plausible in isolation but are fraudulent when viewed across the full email-plus-voice sequence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-01 — Security Continuous MonitoringTOAD detection depends on monitoring anomalous campaign behavior across mail telemetry.
Recommendation — Correlate email and callback patterns in continuous monitoring to spot authenticated phishing campaigns.
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingCross-message correlation and campaign analysis require review of logs and alerts.
Recommendation — Review mail and callback telemetry to detect coordinated TOAD campaigns.
CIS Controls v8CIS-8 — Audit Log ManagementBehavioral detection relies on retaining and analyzing mail and communication events.
Recommendation — Centralize and analyze mail flow and user-report logs for burst and impersonation patterns.
MITRE ATT&CKT1566 — PhishingTOAD is a phishing technique that uses trusted mail to initiate social engineering.
Recommendation — Map TOAD indicators to phishing techniques and hunt for multi-stage delivery patterns.
OWASP API Security Top 10API2 — Broken AuthenticationAuthenticated email can still be abused, illustrating why authentication signals alone are insufficient.
Recommendation — Treat successful authentication as one signal and validate the business context separately.

Practitioner Guidance

What to prioritise: Build detections that score campaign context first, then message content. If the sender-recipient relationship, brand pairing, callback number, and burst pattern do not fit normal business behaviour, treat the message as suspicious even when authentication passes.

What to verify: Confirm that callback numbers resolve to approved business contacts, that the alleged sender normally interacts with the recipient, and that the message fits a known workflow before analysts or users trust it.

Decision rule: If an authenticated email asks for a phone callback tied to payment, credentials, or urgent account action, route it to heightened review and do not rely on the email authentication result as the deciding factor.

Practitioner takeaway: TOAD detection is a correlation problem, not a header-validation problem, so the strongest control is the ability to see whether the message and the follow-on human interaction fit the organisation’s real communication patterns.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org